PatchSiren

gophish CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH gophish CVE published 2026-08-28

CVE-2026-82269

CVE-2026-82269 debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T20:20:17.650Z and was last modified on 2026-09-23T17:17:43.640Z. The NVD entry is currently Deferred. Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware, allowing attackers with valid API keys to bypass these security controls. De [truncated]

HIGH gophish CVE published 2026-06-22

CVE-2026-39904

CVE-2026-39904 is a high-severity denial of service vulnerability in Gophish, a popular open-source phishing toolkit. The vulnerability, which has a CVSS score of 7.1, allows authenticated users with the User role to upload a crafted Office document as an email template attachment, which can cause the server to run out of memory and terminate. This is possible because the ApplyTemplate() function in model [truncated]