← Back to CVEs
CVE-2026-30961
MEDIUM4.3
Description
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunked upload completion path for file requests does not validate the total file size against the per-request MaxSize limit. An attacker with a public file request link can split an oversized file into chunks each under MaxSize and upload them sequentially, bypassing the size restriction entirely. Files up to the server's global MaxFileSizeMB are accepted regardless of the file request's configured limit. This vulnerability is fixed in 2.2.4.
CVE Details
CVSS v3.1 Score4.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published3/13/2026
Last Modified3/17/2026
Sourcenvd
Honeypot Sightings0
Affected Products
forceu:gokapi
Weaknesses (CWE)
CWE-770
References
https://github.com/Forceu/Gokapi/releases/tag/v2.2.4(security-advisories@github.com)
https://github.com/Forceu/Gokapi/security/advisories/GHSA-45vh-rpc8-hxpp(security-advisories@github.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.