HIGH 8.7 NVD
CVE-2026-104057
Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections)
Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigger a Go runtime data race that crashes the process, causing a denial of service that requires operator intervention to restore service.
References
- https://gist.github.com/mansurmavlankulov/022bc672583687ccb34dcf4cb31b6188
- https://www.vulncheck.com/advisories/podgrab-unauthenticated-dos-via-concurrent-map-access
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-10-01 via NVD.
vulnfeed aggregates 9446 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.