CVE-2026-82410
— UNSCOREDpublic exploit availablePublished 2026-09-16 · Updated 2026-09-16
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal goroutines can escape recovery and terminate the server process, causing a denial of service. The remediation introduces routine.SafeWrap to convert recovered panics into regular errors and applies it to the affected internal worker functions. This issue is fixed in versions 0.22.48 and 0.39.7.
Weaknesses
CWE-248
Public exploit & PoC references
- https://github.com/pocketbase/pocketbase/commit/30b4184305904fae0d1b78216c4e3cc34700b220
- https://github.com/pocketbase/pocketbase/commit/f1618ee59b6d1c0308bb474c827a2b1f24b12a95
- https://github.com/pocketbase/pocketbase/discussions/7762
- https://github.com/pocketbase/pocketbase/releases/tag/v0.22.48
- https://github.com/pocketbase/pocketbase/releases/tag/v0.39.7
- https://github.com/pocketbase/pocketbase/security/advisories/GHSA-84vh-m24q-wjjx
All references
- https://github.com/pocketbase/pocketbase/commit/30b4184305904fae0d1b78216c4e3cc34700b220
- https://github.com/pocketbase/pocketbase/commit/f1618ee59b6d1c0308bb474c827a2b1f24b12a95
- https://github.com/pocketbase/pocketbase/discussions/7762
- https://github.com/pocketbase/pocketbase/releases/tag/v0.22.48
- https://github.com/pocketbase/pocketbase/releases/tag/v0.39.7
- https://github.com/pocketbase/pocketbase/security/advisories/GHSA-84vh-m24q-wjjx
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
Related by shared AI tags and CWE weakness class. Browse the full archive.