VDB
CVE-2026-30955
CVE-2026-30955
PUBLISHED
CVSS 6.5 MEDIUM
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users. This vulnerability is fixed in 2.2.4.
EPSS 0.01% · 2.7th percentile
Risk Scores
CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.01%
2.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| forceu | gokapi | 0, 0 |
| Forceu | Gokapi | < 2.2.4, < 2.2.4 |
| github.com | forceu/gokapi | 0, 0 |
Timeline
- Mar 13, 2026 CVE Published
- Mar 14, 2026 EPSS Score
- Mar 15, 2026 EPSS Score
- Mar 16, 2026 EPSS Score
- Mar 17, 2026 EPSS Score
- Mar 17, 2026 Coalition ESS Score
- Mar 17, 2026 Security Advisory
- Mar 18, 2026 EPSS Score
- Mar 19, 2026 EPSS Score
- Mar 20, 2026 EPSS Score
- Mar 21, 2026 EPSS Score
- Mar 22, 2026 EPSS Score