{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/pocketbase/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pocketbase:pocketbase:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-82410"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PocketBase (\u003c 0.22.48, \u003e= 0.23.0, \u003c 0.39.7)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["PocketBase"],"content_html":"\u003cp\u003ePocketBase, a Go-based backend-as-a-service platform, contains a vulnerability where internal child or worker goroutines do not properly handle panics. While the application's request-handling middleware includes standard panic recovery, internal background processes were previously exposed. If an attacker identifies a condition that triggers a panic within these worker functions, the resulting uncaught exception causes the entire server process to crash, leading to a denial-of-service (DoS) condition. This issue was addressed by introducing a \u003ccode\u003eroutine.SafeWrap(f)\u003c/code\u003e helper function across all internal worker processes to intercept and recover from panics, converting them into manageable errors. The vulnerability is tracked as CVE-2026-82410 and affects multiple version branches. Administrators are urged to update to the latest patched releases to restore process stability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial-of-service, as the entire PocketBase server process terminates upon the occurrence of a triggered panic. This impacts availability for all services hosted on the instance. The issue affects users running versions prior to v0.22.48 and versions between v0.23.0 and v0.39.7.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch PocketBase to version v0.39.7 or v0.22.48 immediately to integrate the \u003ccode\u003eroutine.SafeWrap\u003c/code\u003e error handling for all worker goroutines.\u003c/li\u003e\n\u003cli\u003eAudit server logs for unexpected process crashes or Go runtime panic stacks that coincide with specific user-initiated API requests or background tasks.\u003c/li\u003e\n\u003cli\u003eMonitor service availability metrics for frequent restarts of the PocketBase process, which may indicate an ongoing attempt to exploit CVE-2026-82410.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T19:14:41Z","date_published":"2026-09-17T19:14:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pocketbase-panic/","summary":"PocketBase is susceptible to a denial-of-service vulnerability (CVE-2026-82410) where unhandled panics in internal worker goroutines trigger unexpected server process termination.","title":"Denial of Service via Unhandled Panics in PocketBase Worker Goroutines","url":"https://feed.craftedsignal.io/briefs/2026-09-pocketbase-panic/"}],"language":"en","title":"CraftedSignal Threat Feed - PocketBase","version":"https://jsonfeed.org/version/1.1"}