data/reports: add GO-2026-6489 - data/reports/GO-2026-6489.yaml Fixes golang/vulndb#6489 Change-Id: I695a3533bf0a19e11627622e30c26e5d399b2dab Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/845425 LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Auto-Submit: Ian Alexander <jitsu@google.com> Reviewed-by: Nicholas Husin <husin@google.com> Reviewed-by: Nicholas Husin <nsh@golang.org>
diff --git a/data/osv/GO-2026-6489.json b/data/osv/GO-2026-6489.json new file mode 100644 index 0000000..033a021 --- /dev/null +++ b/data/osv/GO-2026-6489.json
@@ -0,0 +1,472 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6489", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-82410", + "GHSA-84vh-m24q-wjjx" + ], + "summary": "Pocketbase: Unhandled panic in worker goroutines in github.com/pocketbase/pocketbase", + "details": "Pocketbase: Unhandled panic in worker goroutines in github.com/pocketbase/pocketbase", + "affected": [ + { + "package": { + "name": "github.com/pocketbase/pocketbase", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.22.48" + }, + { + "introduced": "0.23.0" + }, + { + "fixed": "0.39.7" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/pocketbase/pocketbase/tools/cron", + "symbols": [ + "Cron.SetInterval", + "Cron.Start" + ] + }, + { + "path": "github.com/pocketbase/pocketbase/tools/search", + "symbols": [ + "Provider.Exec", + "Provider.ParseAndExec" + ] + }, + { + "path": "github.com/pocketbase/pocketbase/plugins/jsvm", + "symbols": [ + "BindApis", + "BindCore", + "BindDbx", + "BindFilepath", + "BindFilesystem", + "BindForms", + "BindHTTP", + "BindMails", + "BindOS", + "BindSecurity", + "MustRegister", + "Register", + "plugin.watchHooks" + ] + }, + { + "path": "github.com/pocketbase/pocketbase/core", + "symbols": [ + "AuthAlertConfig.Validate", + "AuthOrigin.CollectionRef", + "AuthOrigin.Created", + "AuthOrigin.Fingerprint", + "AuthOrigin.RecordRef", + "AuthOrigin.SetCollectionRef", + "AuthOrigin.SetFingerprint", + "AuthOrigin.SetRecordRef", + "AuthOrigin.Updated", + "AutodateField.Intercept", + "AutodateField.PrepareValue", + "AutodateField.ValidateSettings", + "BackupsConfig.Validate", + "BaseApp.AuxDelete", + "BaseApp.AuxDeleteWithContext", + "BaseApp.AuxHasTable", + "BaseApp.AuxRunInTransaction", + "BaseApp.AuxSave", + "BaseApp.AuxSaveNoValidate", + "BaseApp.AuxSaveNoValidateWithContext", + "BaseApp.AuxSaveWithContext", + "BaseApp.AuxVacuum", + "BaseApp.Bootstrap", + "BaseApp.CanAccessRecord", + "BaseApp.CountRecords", + "BaseApp.CreateBackup", + "BaseApp.CreateViewFields", + "BaseApp.Delete", + "BaseApp.DeleteAllAuthOriginsByRecord", + "BaseApp.DeleteAllExternalAuthsByRecord", + "BaseApp.DeleteAllMFAsByRecord", + "BaseApp.DeleteAllOTPsByRecord", + "BaseApp.DeleteExpiredMFAs", + "BaseApp.DeleteExpiredOTPs", + "BaseApp.DeleteOldLogs", + "BaseApp.DeleteTable", + "BaseApp.DeleteView", + "BaseApp.DeleteWithContext", + "BaseApp.DryRunView", + "BaseApp.ExpandRecord", + "BaseApp.ExpandRecords", + "BaseApp.FindAllAuthOriginsByCollection", + "BaseApp.FindAllAuthOriginsByRecord", + "BaseApp.FindAllCollections", + "BaseApp.FindAllExternalAuthsByCollection", + "BaseApp.FindAllExternalAuthsByRecord", + "BaseApp.FindAllMFAsByCollection", + "BaseApp.FindAllMFAsByRecord", + "BaseApp.FindAllOTPsByCollection", + "BaseApp.FindAllOTPsByRecord", + "BaseApp.FindAllRecords", + "BaseApp.FindAuthOriginById", + "BaseApp.FindAuthOriginByRecordAndFingerprint", + "BaseApp.FindAuthRecordByEmail", + "BaseApp.FindAuthRecordByToken", + "BaseApp.FindCachedCollectionByNameOrId", + "BaseApp.FindCachedCollectionReferences", + "BaseApp.FindCollectionByNameOrId", + "BaseApp.FindCollectionReferences", + "BaseApp.FindFirstExternalAuthByExpr", + "BaseApp.FindFirstRecordByData", + "BaseApp.FindFirstRecordByFilter", + "BaseApp.FindLogById", + "BaseApp.FindMFAById", + "BaseApp.FindOTPById", + "BaseApp.FindRecordById", + "BaseApp.FindRecordByViewFile", + "BaseApp.FindRecordsByFilter", + "BaseApp.FindRecordsByIds", + "BaseApp.HasTable", + "BaseApp.ImportCollections", + "BaseApp.ImportCollectionsByMarshaledJSON", + "BaseApp.IsCollectionNameUnique", + "BaseApp.LogsStats", + "BaseApp.NewBackupsFilesystem", + "BaseApp.NewFilesystem", + "BaseApp.RecordQuery", + "BaseApp.ReloadCachedCollections", + "BaseApp.ReloadSettings", + "BaseApp.ResetBootstrapState", + "BaseApp.Restart", + "BaseApp.RestoreBackup", + "BaseApp.RunAllMigrations", + "BaseApp.RunAppMigrations", + "BaseApp.RunInTransaction", + "BaseApp.RunSystemMigrations", + "BaseApp.Save", + "BaseApp.SaveNoValidate", + "BaseApp.SaveNoValidateWithContext", + "BaseApp.SaveView", + "BaseApp.SaveWithContext", + "BaseApp.SyncRecordTableSchema", + "BaseApp.TableColumns", + "BaseApp.TableIndexes", + "BaseApp.TableInfo", + "BaseApp.TruncateCollection", + "BaseApp.Vacuum", + "BaseApp.Validate", + "BaseApp.ValidateWithContext", + "BaseApp.initLogger", + "BatchConfig.Validate", + "BoolField.PrepareValue", + "BoolField.ValidateSettings", + "Collection.AddIndex", + "Collection.DBExport", + "Collection.GetIndex", + "Collection.MarshalJSON", + "Collection.PostScan", + "Collection.RemoveIndex", + "Collection.String", + "Collection.UnmarshalJSON", + "DateField.PrepareValue", + "DateField.ValidateSettings", + "DateField.ValidateValue", + "DefaultDBConnect", + "DefaultFieldHelpValidationRule", + "DefaultFieldIdValidationRule", + "DefaultFieldNameValidationRule", + "EditorField.PrepareValue", + "EditorField.ValidateSettings", + "EmailField.PrepareValue", + "EmailField.ValidateSettings", + "EmailField.ValidateValue", + "EmailTemplate.Resolve", + "EmailTemplate.Validate", + "ExternalAuth.CollectionRef", + "ExternalAuth.Created", + "ExternalAuth.Provider", + "ExternalAuth.ProviderId", + "ExternalAuth.RecordRef", + "ExternalAuth.SetCollectionRef", + "ExternalAuth.SetProvider", + "ExternalAuth.SetProviderId", + "ExternalAuth.SetRecordRef", + "ExternalAuth.Updated", + "FieldsList.Add", + "FieldsList.AddAt", + "FieldsList.AddMarshaledJSON", + "FieldsList.AddMarshaledJSONAt", + "FieldsList.Clone", + "FieldsList.MarshalJSON", + "FieldsList.Scan", + "FieldsList.String", + "FieldsList.UnmarshalJSON", + "FieldsList.Value", + "FileField.DriverValue", + "FileField.FindGetter", + "FileField.Intercept", + "FileField.PrepareValue", + "FileField.ValidateSettings", + "FileField.ValidateValue", + "GeoPointField.PrepareValue", + "GeoPointField.ValidateSettings", + "InternalRequest.Validate", + "JSONField.PrepareValue", + "JSONField.ValidateSettings", + "JSONField.ValidateValue", + "LogsConfig.Validate", + "MFA.CollectionRef", + "MFA.Created", + "MFA.HasExpired", + "MFA.Method", + "MFA.RecordRef", + "MFA.SetCollectionRef", + "MFA.SetMethod", + "MFA.SetRecordRef", + "MFA.Updated", + "MFAConfig.Validate", + "MetaConfig.Validate", + "MigrationsRunner.Down", + "MigrationsRunner.RemoveMissingAppliedMigrations", + "MigrationsRunner.Run", + "MigrationsRunner.Up", + "NewAuthCollection", + "NewAuthOrigin", + "NewBaseApp", + "NewBaseCollection", + "NewCollection", + "NewExternalAuth", + "NewFieldsList", + "NewMFA", + "NewOTP", + "NewRecord", + "NewRecordFieldResolver", + "NewViewCollection", + "NumberField.PrepareValue", + "NumberField.ValidateSettings", + "OAuth2Config.Validate", + "OAuth2ProviderConfig.InitProvider", + "OAuth2ProviderConfig.Validate", + "OTP.CollectionRef", + "OTP.Created", + "OTP.HasExpired", + "OTP.RecordRef", + "OTP.SentTo", + "OTP.SetCollectionRef", + "OTP.SetRecordRef", + "OTP.SetSentTo", + "OTP.Updated", + "OTPConfig.Validate", + "PasswordAuthConfig.Validate", + "PasswordField.Intercept", + "PasswordField.PrepareValue", + "PasswordField.ValidateSettings", + "PasswordField.ValidateValue", + "PasswordFieldValue.Validate", + "RateLimitRule.String", + "RateLimitRule.Validate", + "RateLimitsConfig.MarshalJSON", + "RateLimitsConfig.Validate", + "Record.BaseFilesPath", + "Record.Clone", + "Record.DBExport", + "Record.Email", + "Record.EmailVisibility", + "Record.FieldsData", + "Record.FindFileFieldByFile", + "Record.Fresh", + "Record.Get", + "Record.GetBool", + "Record.GetDateTime", + "Record.GetFloat", + "Record.GetGeoPoint", + "Record.GetInt", + "Record.GetString", + "Record.GetStringSlice", + "Record.GetUnsavedFiles", + "Record.GetUploadedFiles", + "Record.Load", + "Record.MarshalJSON", + "Record.NewAuthToken", + "Record.NewEmailChangeToken", + "Record.NewFileToken", + "Record.NewPasswordResetToken", + "Record.NewStaticAuthToken", + "Record.NewVerificationToken", + "Record.Original", + "Record.PostScan", + "Record.PublicExport", + "Record.RefreshTokenKey", + "Record.ReplaceModifiers", + "Record.Set", + "Record.SetEmail", + "Record.SetEmailVisibility", + "Record.SetIfFieldExists", + "Record.SetPassword", + "Record.SetRandomPassword", + "Record.SetRaw", + "Record.SetTokenKey", + "Record.SetVerified", + "Record.TokenKey", + "Record.UnmarshalJSON", + "Record.UnmarshalJSONField", + "Record.ValidatePassword", + "Record.Verified", + "RecordFieldResolver.Resolve", + "RecordFieldResolver.UpdateQuery", + "RelationField.DriverValue", + "RelationField.PrepareValue", + "RelationField.ValidateSettings", + "RelationField.ValidateValue", + "RequestEvent.RealIP", + "RequestEvent.RequestInfo", + "RequestInfo.Clone", + "S3Config.Validate", + "SMTPConfig.MarshalJSON", + "SMTPConfig.Validate", + "SelectField.DriverValue", + "SelectField.PrepareValue", + "SelectField.ValidateSettings", + "SelectField.ValidateValue", + "Settings.Clone", + "Settings.DBExport", + "Settings.MarshalJSON", + "Settings.Merge", + "Settings.PostValidate", + "Settings.String", + "TextField.Intercept", + "TextField.PrepareValue", + "TextField.ValidatePlainValue", + "TextField.ValidateSettings", + "TextField.ValidateValue", + "TokenConfig.Validate", + "TrustedProxyConfig.MarshalJSON", + "URLField.PrepareValue", + "URLField.ValidateSettings", + "URLField.ValidateValue", + "createNotifyDirWatcher", + "dualDBBuilder.AddColumn", + "dualDBBuilder.AddForeignKey", + "dualDBBuilder.AddPrimaryKey", + "dualDBBuilder.AlterColumn", + "dualDBBuilder.CreateIndex", + "dualDBBuilder.CreateTable", + "dualDBBuilder.CreateUniqueIndex", + "dualDBBuilder.Delete", + "dualDBBuilder.DropColumn", + "dualDBBuilder.DropForeignKey", + "dualDBBuilder.DropIndex", + "dualDBBuilder.DropPrimaryKey", + "dualDBBuilder.DropTable", + "dualDBBuilder.GeneratePlaceholder", + "dualDBBuilder.Insert", + "dualDBBuilder.Model", + "dualDBBuilder.NewQuery", + "dualDBBuilder.RenameColumn", + "dualDBBuilder.RenameTable", + "dualDBBuilder.TruncateTable", + "dualDBBuilder.Update", + "dualDBBuilder.Upsert", + "fieldWithType.UnmarshalJSON", + "replaceWithExpression.Build" + ] + }, + { + "path": "github.com/pocketbase/pocketbase/daos", + "symbols": [ + "Dao.parseQueryToFields" + ] + }, + { + "path": "github.com/pocketbase/pocketbase/tools/filesystem/internal/s3lite", + "symbols": [ + "writer.open" + ] + }, + { + "path": "github.com/pocketbase/pocketbase/apis", + "symbols": [ + "backupApi.restore", + "batchProcessor.Process", + "realtimeBroadcastDryCacheKey", + "realtimeBroadcastRecord", + "realtimeUnsetClientsAuthByCollection", + "realtimeUnsetClientsAuthByRecordModelOrProxy", + "realtimeUnsetDryCacheKey", + "realtimeUpdateClientsAuth" + ] + }, + { + "path": "github.com/pocketbase/pocketbase", + "symbols": [ + "New", + "NewWithConfig", + "PocketBase.Execute", + "PocketBase.Start", + "coloredWriter.Write" + ] + }, + { + "path": "github.com/pocketbase/pocketbase/tools/filesystem/internal/s3blob", + "symbols": [ + "writer.Close", + "writer.Write", + "writer.open" + ] + }, + { + "path": "github.com/pocketbase/pocketbase/tools/filesystem/internal/s3blob/s3", + "symbols": [ + "Uploader.Upload", + "Uploader.multipartUpload" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://github.com/pocketbase/pocketbase/security/advisories/GHSA-84vh-m24q-wjjx" + }, + { + "type": "FIX", + "url": "https://github.com/pocketbase/pocketbase/commit/30b4184305904fae0d1b78216c4e3cc34700b220" + }, + { + "type": "FIX", + "url": "https://github.com/pocketbase/pocketbase/commit/f1618ee59b6d1c0308bb474c827a2b1f24b12a95" + }, + { + "type": "WEB", + "url": "https://github.com/pocketbase/pocketbase/discussions/7762" + }, + { + "type": "WEB", + "url": "https://github.com/pocketbase/pocketbase/releases/tag/v0.22.48" + }, + { + "type": "WEB", + "url": "https://github.com/pocketbase/pocketbase/releases/tag/v0.39.7" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6489", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6489.yaml b/data/reports/GO-2026-6489.yaml new file mode 100644 index 0000000..3c71b92 --- /dev/null +++ b/data/reports/GO-2026-6489.yaml
@@ -0,0 +1,406 @@ +id: GO-2026-6489 +modules: + - module: github.com/pocketbase/pocketbase + versions: + - fixed: 0.22.48 + - introduced: 0.23.0 + - fixed: 0.39.7 + vulnerable_at: 0.39.6 + packages: + - package: github.com/pocketbase/pocketbase/tools/cron + symbols: + - Cron.Start + derived_symbols: + - Cron.SetInterval + - package: github.com/pocketbase/pocketbase/tools/search + symbols: + - Provider.Exec + derived_symbols: + - Provider.ParseAndExec + - package: github.com/pocketbase/pocketbase/plugins/jsvm + symbols: + - plugin.watchHooks + derived_symbols: + - BindApis + - BindCore + - BindDbx + - BindFilepath + - BindFilesystem + - BindForms + - BindHTTP + - BindMails + - BindOS + - BindSecurity + - MustRegister + - Register + - package: github.com/pocketbase/pocketbase/core + symbols: + - BaseApp.initLogger + - createNotifyDirWatcher + derived_symbols: + - AuthAlertConfig.Validate + - AuthOrigin.CollectionRef + - AuthOrigin.Created + - AuthOrigin.Fingerprint + - AuthOrigin.RecordRef + - AuthOrigin.SetCollectionRef + - AuthOrigin.SetFingerprint + - AuthOrigin.SetRecordRef + - AuthOrigin.Updated + - AutodateField.Intercept + - AutodateField.PrepareValue + - AutodateField.ValidateSettings + - BackupsConfig.Validate + - BaseApp.AuxDelete + - BaseApp.AuxDeleteWithContext + - BaseApp.AuxHasTable + - BaseApp.AuxRunInTransaction + - BaseApp.AuxSave + - BaseApp.AuxSaveNoValidate + - BaseApp.AuxSaveNoValidateWithContext + - BaseApp.AuxSaveWithContext + - BaseApp.AuxVacuum + - BaseApp.Bootstrap + - BaseApp.CanAccessRecord + - BaseApp.CountRecords + - BaseApp.CreateBackup + - BaseApp.CreateViewFields + - BaseApp.Delete + - BaseApp.DeleteAllAuthOriginsByRecord + - BaseApp.DeleteAllExternalAuthsByRecord + - BaseApp.DeleteAllMFAsByRecord + - BaseApp.DeleteAllOTPsByRecord + - BaseApp.DeleteExpiredMFAs + - BaseApp.DeleteExpiredOTPs + - BaseApp.DeleteOldLogs + - BaseApp.DeleteTable + - BaseApp.DeleteView + - BaseApp.DeleteWithContext + - BaseApp.DryRunView + - BaseApp.ExpandRecord + - BaseApp.ExpandRecords + - BaseApp.FindAllAuthOriginsByCollection + - BaseApp.FindAllAuthOriginsByRecord + - BaseApp.FindAllCollections + - BaseApp.FindAllExternalAuthsByCollection + - BaseApp.FindAllExternalAuthsByRecord + - BaseApp.FindAllMFAsByCollection + - BaseApp.FindAllMFAsByRecord + - BaseApp.FindAllOTPsByCollection + - BaseApp.FindAllOTPsByRecord + - BaseApp.FindAllRecords + - BaseApp.FindAuthOriginById + - BaseApp.FindAuthOriginByRecordAndFingerprint + - BaseApp.FindAuthRecordByEmail + - BaseApp.FindAuthRecordByToken + - BaseApp.FindCachedCollectionByNameOrId + - BaseApp.FindCachedCollectionReferences + - BaseApp.FindCollectionByNameOrId + - BaseApp.FindCollectionReferences + - BaseApp.FindFirstExternalAuthByExpr + - BaseApp.FindFirstRecordByData + - BaseApp.FindFirstRecordByFilter + - BaseApp.FindLogById + - BaseApp.FindMFAById + - BaseApp.FindOTPById + - BaseApp.FindRecordById + - BaseApp.FindRecordByViewFile + - BaseApp.FindRecordsByFilter + - BaseApp.FindRecordsByIds + - BaseApp.HasTable + - BaseApp.ImportCollections + - BaseApp.ImportCollectionsByMarshaledJSON + - BaseApp.IsCollectionNameUnique + - BaseApp.LogsStats + - BaseApp.NewBackupsFilesystem + - BaseApp.NewFilesystem + - BaseApp.RecordQuery + - BaseApp.ReloadCachedCollections + - BaseApp.ReloadSettings + - BaseApp.ResetBootstrapState + - BaseApp.Restart + - BaseApp.RestoreBackup + - BaseApp.RunAllMigrations + - BaseApp.RunAppMigrations + - BaseApp.RunInTransaction + - BaseApp.RunSystemMigrations + - BaseApp.Save + - BaseApp.SaveNoValidate + - BaseApp.SaveNoValidateWithContext + - BaseApp.SaveView + - BaseApp.SaveWithContext + - BaseApp.SyncRecordTableSchema + - BaseApp.TableColumns + - BaseApp.TableIndexes + - BaseApp.TableInfo + - BaseApp.TruncateCollection + - BaseApp.Vacuum + - BaseApp.Validate + - BaseApp.ValidateWithContext + - BatchConfig.Validate + - BoolField.PrepareValue + - BoolField.ValidateSettings + - Collection.AddIndex + - Collection.DBExport + - Collection.GetIndex + - Collection.MarshalJSON + - Collection.PostScan + - Collection.RemoveIndex + - Collection.String + - Collection.UnmarshalJSON + - DateField.PrepareValue + - DateField.ValidateSettings + - DateField.ValidateValue + - DefaultDBConnect + - DefaultFieldHelpValidationRule + - DefaultFieldIdValidationRule + - DefaultFieldNameValidationRule + - EditorField.PrepareValue + - EditorField.ValidateSettings + - EmailField.PrepareValue + - EmailField.ValidateSettings + - EmailField.ValidateValue + - EmailTemplate.Resolve + - EmailTemplate.Validate + - ExternalAuth.CollectionRef + - ExternalAuth.Created + - ExternalAuth.Provider + - ExternalAuth.ProviderId + - ExternalAuth.RecordRef + - ExternalAuth.SetCollectionRef + - ExternalAuth.SetProvider + - ExternalAuth.SetProviderId + - ExternalAuth.SetRecordRef + - ExternalAuth.Updated + - FieldsList.Add + - FieldsList.AddAt + - FieldsList.AddMarshaledJSON + - FieldsList.AddMarshaledJSONAt + - FieldsList.Clone + - FieldsList.MarshalJSON + - FieldsList.Scan + - FieldsList.String + - FieldsList.UnmarshalJSON + - FieldsList.Value + - FileField.DriverValue + - FileField.FindGetter + - FileField.Intercept + - FileField.PrepareValue + - FileField.ValidateSettings + - FileField.ValidateValue + - GeoPointField.PrepareValue + - GeoPointField.ValidateSettings + - InternalRequest.Validate + - JSONField.PrepareValue + - JSONField.ValidateSettings + - JSONField.ValidateValue + - LogsConfig.Validate + - MFA.CollectionRef + - MFA.Created + - MFA.HasExpired + - MFA.Method + - MFA.RecordRef + - MFA.SetCollectionRef + - MFA.SetMethod + - MFA.SetRecordRef + - MFA.Updated + - MFAConfig.Validate + - MetaConfig.Validate + - MigrationsRunner.Down + - MigrationsRunner.RemoveMissingAppliedMigrations + - MigrationsRunner.Run + - MigrationsRunner.Up + - NewAuthCollection + - NewAuthOrigin + - NewBaseApp + - NewBaseCollection + - NewCollection + - NewExternalAuth + - NewFieldsList + - NewMFA + - NewOTP + - NewRecord + - NewRecordFieldResolver + - NewViewCollection + - NumberField.PrepareValue + - NumberField.ValidateSettings + - OAuth2Config.Validate + - OAuth2ProviderConfig.InitProvider + - OAuth2ProviderConfig.Validate + - OTP.CollectionRef + - OTP.Created + - OTP.HasExpired + - OTP.RecordRef + - OTP.SentTo + - OTP.SetCollectionRef + - OTP.SetRecordRef + - OTP.SetSentTo + - OTP.Updated + - OTPConfig.Validate + - PasswordAuthConfig.Validate + - PasswordField.Intercept + - PasswordField.PrepareValue + - PasswordField.ValidateSettings + - PasswordField.ValidateValue + - PasswordFieldValue.Validate + - RateLimitRule.String + - RateLimitRule.Validate + - RateLimitsConfig.MarshalJSON + - RateLimitsConfig.Validate + - Record.BaseFilesPath + - Record.Clone + - Record.DBExport + - Record.Email + - Record.EmailVisibility + - Record.FieldsData + - Record.FindFileFieldByFile + - Record.Fresh + - Record.Get + - Record.GetBool + - Record.GetDateTime + - Record.GetFloat + - Record.GetGeoPoint + - Record.GetInt + - Record.GetString + - Record.GetStringSlice + - Record.GetUnsavedFiles + - Record.GetUploadedFiles + - Record.Load + - Record.MarshalJSON + - Record.NewAuthToken + - Record.NewEmailChangeToken + - Record.NewFileToken + - Record.NewPasswordResetToken + - Record.NewStaticAuthToken + - Record.NewVerificationToken + - Record.Original + - Record.PostScan + - Record.PublicExport + - Record.RefreshTokenKey + - Record.ReplaceModifiers + - Record.Set + - Record.SetEmail + - Record.SetEmailVisibility + - Record.SetIfFieldExists + - Record.SetPassword + - Record.SetRandomPassword + - Record.SetRaw + - Record.SetTokenKey + - Record.SetVerified + - Record.TokenKey + - Record.UnmarshalJSON + - Record.UnmarshalJSONField + - Record.ValidatePassword + - Record.Verified + - RecordFieldResolver.Resolve + - RecordFieldResolver.UpdateQuery + - RelationField.DriverValue + - RelationField.PrepareValue + - RelationField.ValidateSettings + - RelationField.ValidateValue + - RequestEvent.RealIP + - RequestEvent.RequestInfo + - RequestInfo.Clone + - S3Config.Validate + - SMTPConfig.MarshalJSON + - SMTPConfig.Validate + - SelectField.DriverValue + - SelectField.PrepareValue + - SelectField.ValidateSettings + - SelectField.ValidateValue + - Settings.Clone + - Settings.DBExport + - Settings.MarshalJSON + - Settings.Merge + - Settings.PostValidate + - Settings.String + - TextField.Intercept + - TextField.PrepareValue + - TextField.ValidatePlainValue + - TextField.ValidateSettings + - TextField.ValidateValue + - TokenConfig.Validate + - TrustedProxyConfig.MarshalJSON + - URLField.PrepareValue + - URLField.ValidateSettings + - URLField.ValidateValue + - dualDBBuilder.AddColumn + - dualDBBuilder.AddForeignKey + - dualDBBuilder.AddPrimaryKey + - dualDBBuilder.AlterColumn + - dualDBBuilder.CreateIndex + - dualDBBuilder.CreateTable + - dualDBBuilder.CreateUniqueIndex + - dualDBBuilder.Delete + - dualDBBuilder.DropColumn + - dualDBBuilder.DropForeignKey + - dualDBBuilder.DropIndex + - dualDBBuilder.DropPrimaryKey + - dualDBBuilder.DropTable + - dualDBBuilder.GeneratePlaceholder + - dualDBBuilder.Insert + - dualDBBuilder.Model + - dualDBBuilder.NewQuery + - dualDBBuilder.RenameColumn + - dualDBBuilder.RenameTable + - dualDBBuilder.TruncateTable + - dualDBBuilder.Update + - dualDBBuilder.Upsert + - fieldWithType.UnmarshalJSON + - replaceWithExpression.Build + - package: github.com/pocketbase/pocketbase/daos + symbols: + - Dao.parseQueryToFields + skip_fix: build errors during static analysis + - package: github.com/pocketbase/pocketbase/tools/filesystem/internal/s3lite + symbols: + - writer.open + skip_fix: build errors during static analysis + - package: github.com/pocketbase/pocketbase/apis + symbols: + - backupApi.restore + - realtimeUnsetClientsAuthByCollection + - realtimeBroadcastRecord + - realtimeUnsetClientsAuthByRecordModelOrProxy + - batchProcessor.Process + - realtimeUpdateClientsAuth + - realtimeBroadcastDryCacheKey + - realtimeUnsetDryCacheKey + skip_fix: build errors during static analysis + - package: github.com/pocketbase/pocketbase + symbols: + - PocketBase.Execute + derived_symbols: + - New + - NewWithConfig + - PocketBase.Start + - coloredWriter.Write + - package: github.com/pocketbase/pocketbase/tools/filesystem/internal/s3blob + symbols: + - writer.open + derived_symbols: + - writer.Close + - writer.Write + - package: github.com/pocketbase/pocketbase/tools/filesystem/internal/s3blob/s3 + symbols: + - Uploader.multipartUpload + derived_symbols: + - Uploader.Upload +summary: |- + Pocketbase: Unhandled panic in worker goroutines in + github.com/pocketbase/pocketbase +cves: + - CVE-2026-82410 +ghsas: + - GHSA-84vh-m24q-wjjx +references: + - advisory: https://github.com/pocketbase/pocketbase/security/advisories/GHSA-84vh-m24q-wjjx + - fix: https://github.com/pocketbase/pocketbase/commit/30b4184305904fae0d1b78216c4e3cc34700b220 + - fix: https://github.com/pocketbase/pocketbase/commit/f1618ee59b6d1c0308bb474c827a2b1f24b12a95 + - web: https://github.com/pocketbase/pocketbase/discussions/7762 + - web: https://github.com/pocketbase/pocketbase/releases/tag/v0.22.48 + - web: https://github.com/pocketbase/pocketbase/releases/tag/v0.39.7 +source: + id: GHSA-84vh-m24q-wjjx + created: 2026-10-05T10:40:49.642045-04:00 +review_status: REVIEWED