CVE-2026-104057

🟡 Monitoruj

Brak synchronizacji w Podgrab umożliwia zdalne wywołanie awarii usługi przez atakującego.

CVSS
7.5
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigger a Go runtime data race that crashes the process, causing a denial of service that requires operator intervention to restore service.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-10-01 19:17:19 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:47:49 UTC
Referencje