CVE-2026-48154: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in pilinux gorest
CVE-2026-48154 is a race condition vulnerability in pilinux gorest versions prior to 1.12.2. The issue arises from an unsynchronized package-level map used to store 2FA secrets, which is accessed concurrently by multiple HTTP handlers. This can cause the Go runtime to crash the process due to unsynchronized concurrent map access. The impact is a high availability disruption without confidentiality or integrity loss. The vulnerability has been fixed in version 1.12.2.
AI Analysis
Technical Summary
pilinux gorest, a Golang RESTful API starter kit, contains a race condition in versions before 1.12.2 in the nMemorySecret2FA component. This component uses a package-level map to store two-factor authentication secrets without synchronization. Multiple HTTP handlers concurrently read and write to this map, causing unsynchronized concurrent map access. Go's runtime treats such unsynchronized concurrent map access as a fatal error, leading to process crashes. This vulnerability results in repeatable denial of service due to process crashes but does not affect confidentiality or integrity. The issue is resolved in gorest version 1.12.2.
Potential Impact
The vulnerability allows an attacker to repeatedly trigger a race condition that crashes the gorest process, causing a denial of service and impacting availability. There are no confidentiality or integrity impacts reported.
Mitigation Recommendations
This vulnerability has been fixed in gorest version 1.12.2. Users should upgrade to version 1.12.2 or later to remediate this issue. No other mitigation is indicated.
CVE-2026-48154: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in pilinux gorest
Description
CVE-2026-48154 is a race condition vulnerability in pilinux gorest versions prior to 1.12.2. The issue arises from an unsynchronized package-level map used to store 2FA secrets, which is accessed concurrently by multiple HTTP handlers. This can cause the Go runtime to crash the process due to unsynchronized concurrent map access. The impact is a high availability disruption without confidentiality or integrity loss. The vulnerability has been fixed in version 1.12.2.
CVSS v3.1
Score 5.9medium
Affected software
pkg:golang/github.com/pilinux/gorestRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
pilinux gorest, a Golang RESTful API starter kit, contains a race condition in versions before 1.12.2 in the nMemorySecret2FA component. This component uses a package-level map to store two-factor authentication secrets without synchronization. Multiple HTTP handlers concurrently read and write to this map, causing unsynchronized concurrent map access. Go's runtime treats such unsynchronized concurrent map access as a fatal error, leading to process crashes. This vulnerability results in repeatable denial of service due to process crashes but does not affect confidentiality or integrity. The issue is resolved in gorest version 1.12.2.
Potential Impact
The vulnerability allows an attacker to repeatedly trigger a race condition that crashes the gorest process, causing a denial of service and impacting availability. There are no confidentiality or integrity impacts reported.
Mitigation Recommendations
This vulnerability has been fixed in gorest version 1.12.2. Users should upgrade to version 1.12.2 or later to remediate this issue. No other mitigation is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T23:12:43.031Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a724791bf8831d5396138da
Added to database: 08/04/2026, 20:12:01 UTC
Last enriched: 08/04/2026, 20:28:02 UTC
Last updated: 08/04/2026, 20:29:32 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.