CVE-2026-104057: Akhilrex Podgrab

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open multiple WebSocket connections to the /ws endpoint and send messages in a loop to trigger a Go runtime data race that crashes the process, causing a denial of service that requires operator intervention to restore service.

Affected products

Published 2026-10-01. Last modified 2026-10-02.