Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigger a Go runtime data race that crashes the process, causing a denial of service that requires operator intervention to restore service. | |
| Title | Podgrab Unauthenticated DoS via Concurrent Map Access in WebSocket Handler | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T19:22:29.119Z
Reserved: 2026-10-01T18:02:50.080Z
Link: CVE-2026-104057
No data.
Status : Received
Published: 2026-10-01T19:17:19.160
Modified: 2026-10-01T19:17:19.160
Link: CVE-2026-104057
No data.
OpenCVE Enrichment
Updated: 2026-10-01T19:30:11Z
-
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')