SCA: security update for github.com/pilinux/gorest (GHSA-cpwg-x64r-rgwg)

medium Tenable Cloud Security Plugin ID 443110

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs.
In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-
level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler/twoFA.go read
from and write to this map concurrently, and because Go's runtime treats unsynchronized concurrent map
access as an unrecoverable fatal error, an attacker can repeatedly trigger this condition to crash the
process on demand. This results in high, repeatable availability impact with no confidentiality or
integrity consequences. This issue has been fixed in version 1.12.2. (CVE-2026-48154)

Solution

Update the github.com/pilinux/gorest library and its related packages to version 1.12.2 or later.

See Also

https://github.com/advisories/GHSA-cpwg-x64r-rgwg

Plugin Details

Severity: Medium

ID: 443110

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 6/12/2026

Updated: 8/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.76

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-48154

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/12/2026

Vulnerability Publication Date: 6/12/2026

Reference Information

CVE: CVE-2026-48154

cwe: CWE-362