CVE-2026-104057: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in akhilrex podgrab
Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigger a Go runtime data race that crashes the process, causing a denial of service that requires operator intervention to restore service.
AI Analysis
Technical Summary
CVE-2026-104057 describes a race condition vulnerability in Podgrab's WebSocket handler where two goroutines, Wshandler and HandleWebsocketMessages, concurrently read and write shared maps (activePlayers and allConnections) without proper mutex synchronization. This unsynchronized access can trigger a Go runtime data race, crashing the process and resulting in a denial of service. The vulnerability is unauthenticated and remotely exploitable via multiple WebSocket connections to the /ws endpoint.
Potential Impact
An unauthenticated remote attacker can cause a denial of service by triggering a race condition that crashes the Podgrab process. This requires operator intervention to restore service, impacting availability. There is no indication of data confidentiality or integrity impact.
Mitigation Recommendations
No patch or official fix information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, operators should consider limiting access to the WebSocket endpoint or implementing external protections to mitigate exploitation.
CVE-2026-104057: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in akhilrex podgrab
Description
Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigger a Go runtime data race that crashes the process, causing a denial of service that requires operator intervention to restore service.
CVSS v4.0
Score 8.7high
Affected software
akhilrex
podgrab
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104057 describes a race condition vulnerability in Podgrab's WebSocket handler where two goroutines, Wshandler and HandleWebsocketMessages, concurrently read and write shared maps (activePlayers and allConnections) without proper mutex synchronization. This unsynchronized access can trigger a Go runtime data race, crashing the process and resulting in a denial of service. The vulnerability is unauthenticated and remotely exploitable via multiple WebSocket connections to the /ws endpoint.
Potential Impact
An unauthenticated remote attacker can cause a denial of service by triggering a race condition that crashes the Podgrab process. This requires operator intervention to restore service, impacting availability. There is no indication of data confidentiality or integrity impact.
Mitigation Recommendations
No patch or official fix information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, operators should consider limiting access to the WebSocket endpoint or implementing external protections to mitigate exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-10-01T18:02:50.080Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abea716a43b0b3b89e139ce
Added to database: 10/01/2026, 18:31:50 UTC
Last enriched: 10/01/2026, 18:46:57 UTC
Last updated: 10/02/2026, 03:48:56 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.