<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Podgrab - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/podgrab/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:23:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/podgrab/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Denial of Service in Podgrab via WebSocket Data Race</title><link>https://feed.craftedsignal.io/briefs/2026-10-podgrab-dos/</link><pubDate>Thu, 01 Oct 2026 20:23:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-podgrab-dos/</guid><description>Podgrab is vulnerable to an unauthenticated denial-of-service attack where an attacker can trigger a Go runtime crash by exploiting unsynchronized concurrent access to shared maps in the WebSocket handler.</description><content:encoded><![CDATA[<p>Podgrab contains a high-severity denial-of-service vulnerability (CVE-2026-104057) originating from unsynchronized concurrent access to shared memory maps. Specifically, the 'activePlayers' and 'allConnections' maps within the application's WebSocket handler are accessed simultaneously by 'Wshandler' and 'HandleWebsocketMessages' goroutines without the use of a mutex or other synchronization primitives. Because the Go runtime panics when concurrent read and write operations are detected on maps, a remote attacker can intentionally trigger this condition. By opening multiple WebSocket connections to the /ws endpoint and flooding the service with messages in a loop, an attacker forces a data race that crashes the entire Podgrab process. The resulting crash requires manual operator intervention to restart the service, making this a persistent denial-of-service condition for exposed instances.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows an unauthenticated remote attacker to crash Podgrab instances, leading to a complete denial of service. The impact is significant for users relying on Podgrab for media management, as the service becomes unavailable until a manual restart occurs. There is no information currently regarding victim count, but any internet-facing Podgrab instance is at risk of disruption.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for administrators and detection engineers:</p>
<ul>
<li>Monitor webserver logs for anomalous high-frequency WebSocket traffic originating from a single source to the /ws endpoint.</li>
<li>Patch Podgrab immediately upon the release of a security update that implements proper mutex locking for the 'activePlayers' and 'allConnections' maps.</li>
<li>Implement rate limiting or connection limits on the /ws endpoint at the reverse proxy or firewall level to mitigate the ease of triggering the crash until a patch is applied.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>web-application</category></item></channel></rss>