Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104057— Podgrab Unauthenticated DoS via Concurrent Map Access in WebSocket Handler

Quick assessment

Affected
akhilrex podgrab
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Podgrab 存在一个未经身份验证的拒绝服务漏洞,该漏洞由其 WebSocket 处理器中对共享映射(activePlayers 和 allConnections)的未同步并发访问引起。具体而言,Wshandler 和 HandleWebsocketMessages 这两个 goroutine(协程)在对这些映射进行读写操作时未使用互斥锁保护。远程攻击者可以建立多个到 /ws 端点的 WebSocket 连接,并在循环中发送消息,从而触发 Go 运行时数据竞争(data race),导致进程崩溃。这将造成拒绝服务

CVSS 7.5 · High EPSS 0.27% · P17

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProduct Version RangeStatus
akhilrex podgrab ≤ 032248091294dbf5b6a439a5afd93788a7cc647f affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104057

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Podgrab Unauthenticated DoS via Concurrent Map Access in WebSocket Handler
Source: CVE Program / CVE List V5
Vulnerability Description
Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigger a Go runtime data race that crashes the process, causing a denial of service that requires operator intervention to restore service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
akhilrex podgrab 0 ~ 032248091294dbf5b6a439a5afd93788a7cc647f -

II. Public POCs for CVE-2026-104057

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104057

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-104057 (1)

Other References for CVE-2026-104057 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104057

No comments yet


Leave a comment