CVE-2026-104058
Received Received - Intake

Podgrab Missing Authentication in WebSocket Route

Vulnerability report for CVE-2026-104058, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated network clients to connect even when PASSWORD is configured. Attackers can join the allConnections set, capture PlayerExists broadcasts containing client-supplied player identifiers, and replay them in a RegisterPlayer message to hijack queue payloads intended for authenticated users, exposing episode IDs, titles, and server-side file paths while potentially disrupting legitimate playback.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Podgrab has a missing authentication vulnerability where the /ws WebSocket route is not properly protected. Instead of being on a BasicAuth-protected router, it is on the root engine, allowing unauthenticated connections even when a password is set. Attackers can join the connection pool, capture player identifiers from broadcasts, and replay them to hijack queue payloads meant for authenticated users.

Detection Guidance

To detect this vulnerability, monitor network traffic for unauthenticated connections to the /ws WebSocket endpoint. Use tools like tcpdump or Wireshark to capture traffic on the expected port and inspect for connections to /ws without prior authentication. Check server logs for unusual PlayerExists broadcasts or RegisterPlayer messages from unknown clients.

Impact Analysis

This vulnerability allows attackers to intercept sensitive data like episode IDs, titles, and file paths. It can also disrupt playback for legitimate users by hijacking their queue payloads. Unauthorized access to the WebSocket endpoint may lead to data exposure or service disruption.

Mitigation Strategies

Immediately update Podgrab to the latest version where the /ws route is properly protected by BasicAuth. If an update is unavailable, restrict access to the /ws endpoint via firewall rules or reverse proxy configurations to allow only trusted IPs. Disable the WebSocket service if not essential.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104058. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart