CVE-2026-30955: Forceu Gokapi

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users. This vulnerability is fixed in 2.2.4.

Affected products

  • Forceu Gokapi: before 2.2.4 (fixed in 2.2.4)

Published 2026-03-13. Last modified 2026-06-17.