PT-2026-93817 · Unknown · Pocketbase

CVE-2026-82410

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pocketbase versions prior to 0.22.48 Pocketbase versions prior to 0.39.7
Description The panic-recovery middleware handles regular requests but does not cover internal child and worker goroutines. A panic within these internal goroutines can bypass recovery mechanisms and terminate the server process, resulting in a denial of service. To address this, the routine.SafeWrap() function was introduced to convert recovered panics into regular errors and apply them to the affected internal worker functions.
Recommendations Update to version 0.22.48. Update to version 0.39.7.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82410
GHSA-84VH-M24Q-WJJX

Affected Products

Pocketbase