CVE-2026-104057
Received Received - Intake

Unauthenticated DoS in Podgrab via WebSocket Race Condition

Vulnerability report for CVE-2026-104057, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigger a Go runtime data race that crashes the process, causing a denial of service that requires operator intervention to restore service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated denial-of-service (DoS) vulnerability in Podgrab caused by unsynchronized concurrent access to shared maps in its WebSocket handler. Multiple goroutines read and write to activePlayers and allConnections maps without a mutex, leading to a Go runtime data race that crashes the process when an attacker sends repeated messages via multiple WebSocket connections to the /ws endpoint.

Detection Guidance

Monitor for excessive WebSocket connections to the /ws endpoint. Check for repeated messages from the same source. Look for Go runtime crashes or panics in logs. Use tools like netstat or ss to track active connections to /ws.

Impact Analysis

An attacker could exploit this to crash the Podgrab service, causing downtime and requiring manual intervention to restore service. Since the /ws endpoint is unauthenticated, anyone can trigger this issue without needing credentials, making it easy to abuse.

Mitigation Strategies

Restrict access to the /ws endpoint by requiring authentication. Add mutex locks to the shared maps (activePlayers and allConnections) in the WebSocket handler code. Update to the latest version of Podgrab if a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104057. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart