CyberRota
Back to database

CVE-2026-43981

UNKNOWN · CVSS N/A EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-05-26 · Last synced: 2026-06-25

CyberRota Analysis

Detaylı analiz gerekiyor.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-43981
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%

Original NVD Description

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since gopher-lua's LState is explicitly not goroutine-safe, concurrent requests race on the shared state causing Lua VM corruption. The Go race detector confirms this immediately under modest concurrency (ab -n 1000 -c 100). This vulnerability is fixed in 1.17.6.