Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4.
02 / AFFECTED SOFTWARE
Affected packages
41 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users. This vulnerability is fixed in 2.2.4.
### Summary An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users. ### Impact Any authenticated user can crash the Gokapi server by sending concurrent large payloads.
Gokapi vulnerable to DoS in E2E Metadata Parser in github.com/forceu/gokapi. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/forceu/gokapi before v2.2.4.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30955.json
- https://github.com/Forceu/Gokapi/releases/tag/v2.2.4
- https://github.com/Forceu/Gokapi/security/advisories/GHSA-qwc6-vc2v-2ggj
- https://nvd.nist.gov/vuln/detail/CVE-2026-30955
- https://github.com/Forceu/Gokapi
- https://pkg.go.dev/vuln/GO-2026-4698