OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104057

HIGH · CVSS 7.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Podgrab is vulnerable to an unauthenticated denial-of-service attack due to unsynchronized access to shared data structures in its WebSocket handler. A remote attacker can exploit this by opening multiple WebSocket connections and sending messages in rapid succession, leading to a crash of the service that necessitates manual intervention to restore. Organizations using Podgrab should prioritize addressing this vulnerability to prevent potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104057
Severity
HIGH
CVSS
7.5
EPSS
0.27%

Original NVD Description

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigger a Go runtime data race that crashes the process, causing a denial of service that requires operator intervention to restore service.