Impact
Podgrab contains an unauthenticated denial‑of‑service flaw caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) within its WebSocket handler. The goroutines handling WebSocket connections read and write these maps without proper mutual exclusion, creating a Go runtime data race. An attacker can open many WebSocket connections to the /ws endpoint and stream messages in a tight loop, triggering the race to crash the process. The crash forces operator intervention to restart the service, resulting in a temporary loss of availability.
Affected Systems
Any deployment of Podgrab from akhilrex is affected. The description does not list a specific version, so all releases of Podgrab contain the flaw. Users running Podgrab should treat all known releases as vulnerable until a patched version is installed.
Risk and Exploitability
The CVSS score of 8.7 classifies this vulnerability as High severity. EPSS data is not available, but the flaw requires only unauthenticated network access to the /ws endpoint, meaning any host on the network or the public Internet can exploit it if connectivity to Podgrab is possible. The vulnerability is not listed in CISA’s KEV catalog, but the ease of exploitation and the impact on service availability make it a significant risk for production deployments.
OpenCVE Enrichment