Impact
PocketBase’s panic‑recovery middleware protects normal request handling, but it does not cover internal worker goroutines. A panic that occurs inside one of these goroutines bypasses recovery and terminates the entire server process, resulting in a denial of service. This flaw is a form of unchecked exception handling (CWE‑248). The vulnerability allows an attacker who can trigger a panic in an internal goroutine to bring the backend down without needing elevated privileges or special network conditions.
Affected Systems
The issue exists in all PocketBase releases prior to v0.22.48 and v0.39.7. The remedy is the introduction of routine.SafeWrap in internal worker functions, which converts recovered panics into normal errors. Both release lines 0.22.48 and 0.39.7 contain the fix, so any version before those is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 classifies this as high severity, while an EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Likely, exploitation would involve sending crafted input or triggering edge cases that cause an internal goroutine to panic during normal API usage or background processing. Because the panic is internal, network access alone does not guarantee success; a component that can drive the application’s code to a panic state is required. However, when such a scenario is achieved, the server processes will terminate immediately, offering a straightforward denial‑of‑service vector.
OpenCVE Enrichment
Github GHSA