Description
Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal goroutines can escape recovery and terminate the server process, causing a denial of service. The remediation introduces routine.SafeWrap to convert recovered panics into regular errors and applies it to the affected internal worker functions. This issue is fixed in versions 0.22.48 and 0.39.7.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

PocketBase’s panic‑recovery middleware protects normal request handling, but it does not cover internal worker goroutines. A panic that occurs inside one of these goroutines bypasses recovery and terminates the entire server process, resulting in a denial of service. This flaw is a form of unchecked exception handling (CWE‑248). The vulnerability allows an attacker who can trigger a panic in an internal goroutine to bring the backend down without needing elevated privileges or special network conditions.

Affected Systems

The issue exists in all PocketBase releases prior to v0.22.48 and v0.39.7. The remedy is the introduction of routine.SafeWrap in internal worker functions, which converts recovered panics into normal errors. Both release lines 0.22.48 and 0.39.7 contain the fix, so any version before those is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.7 classifies this as high severity, while an EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Likely, exploitation would involve sending crafted input or triggering edge cases that cause an internal goroutine to panic during normal API usage or background processing. Because the panic is internal, network access alone does not guarantee success; a component that can drive the application’s code to a panic state is required. However, when such a scenario is achieved, the server processes will terminate immediately, offering a straightforward denial‑of‑service vector.

Generated by OpenCVE AI on September 17, 2026 at 22:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PocketBase to version 0.22.48 or later, which includes the routine.SafeWrap fix for worker goroutines.
  • If custom internal worker goroutines are used, wrap them with routine.SafeWrap or add explicit panic handling to prevent panics from propagating.
  • Deploy a process supervisor or health‑check mechanism (e.g., systemd, Docker restart policies, or external watchdog) to automatically restart PocketBase if it unexpectedly terminates, reducing downtime.

Generated by OpenCVE AI on September 17, 2026 at 22:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-84vh-m24q-wjjx Pocketbase: Unhandled panic in worker goroutines
History

Fri, 18 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Pocketbase
Pocketbase pocketbase
Vendors & Products Pocketbase
Pocketbase pocketbase

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal goroutines can escape recovery and terminate the server process, causing a denial of service. The remediation introduces routine.SafeWrap to convert recovered panics into regular errors and applies it to the affected internal worker functions. This issue is fixed in versions 0.22.48 and 0.39.7.
Title Pocketbase: Unhandled panic in worker goroutines
Weaknesses CWE-248
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Pocketbase Pocketbase
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:15:34.469Z

Reserved: 2026-08-28T22:00:43.513Z

Link: CVE-2026-82410

cve-icon Vulnrichment

Updated: 2026-09-16T15:15:30.795Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:17:54.703

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-82410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:45:02Z

Weaknesses