VDB

CVE-2026-30955

CVE-2026-30955 PUBLISHED CVSS 6.5 MEDIUM

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users. This vulnerability is fixed in 2.2.4.

EPSS 0.01% · 2.7th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.01%
2.7th percentile

Affected Products

VendorProductVersions
forceugokapi0, 0
ForceuGokapi< 2.2.4, < 2.2.4
github.comforceu/gokapi0, 0

Timeline

  • Mar 13, 2026 CVE Published
  • Mar 14, 2026 EPSS Score
  • Mar 15, 2026 EPSS Score
  • Mar 16, 2026 EPSS Score
  • Mar 17, 2026 EPSS Score
  • Mar 17, 2026 Coalition ESS Score
  • Mar 17, 2026 Security Advisory
  • Mar 18, 2026 EPSS Score
  • Mar 19, 2026 EPSS Score
  • Mar 20, 2026 EPSS Score
  • Mar 21, 2026 EPSS Score
  • Mar 22, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›