LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-30955

forceu · gokapi

Published
CVSS6.5
Severitymedium
WeaknessCWE-400
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users. This vulnerability is fixed in 2.2.4.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-30955

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-30955.