data/reports: add GO-2026-6489

  - data/reports/GO-2026-6489.yaml

Fixes golang/vulndb#6489

Change-Id: I695a3533bf0a19e11627622e30c26e5d399b2dab
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/845425
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Auto-Submit: Ian Alexander <jitsu@google.com>
Reviewed-by: Nicholas Husin <husin@google.com>
Reviewed-by: Nicholas Husin <nsh@golang.org>
diff --git a/data/osv/GO-2026-6489.json b/data/osv/GO-2026-6489.json
new file mode 100644
index 0000000..033a021
--- /dev/null
+++ b/data/osv/GO-2026-6489.json
@@ -0,0 +1,472 @@
+{
+  "schema_version": "1.3.1",
+  "id": "GO-2026-6489",
+  "modified": "0001-01-01T00:00:00Z",
+  "published": "0001-01-01T00:00:00Z",
+  "aliases": [
+    "CVE-2026-82410",
+    "GHSA-84vh-m24q-wjjx"
+  ],
+  "summary": "Pocketbase: Unhandled panic in worker goroutines in github.com/pocketbase/pocketbase",
+  "details": "Pocketbase: Unhandled panic in worker goroutines in github.com/pocketbase/pocketbase",
+  "affected": [
+    {
+      "package": {
+        "name": "github.com/pocketbase/pocketbase",
+        "ecosystem": "Go"
+      },
+      "ranges": [
+        {
+          "type": "SEMVER",
+          "events": [
+            {
+              "introduced": "0"
+            },
+            {
+              "fixed": "0.22.48"
+            },
+            {
+              "introduced": "0.23.0"
+            },
+            {
+              "fixed": "0.39.7"
+            }
+          ]
+        }
+      ],
+      "ecosystem_specific": {
+        "imports": [
+          {
+            "path": "github.com/pocketbase/pocketbase/tools/cron",
+            "symbols": [
+              "Cron.SetInterval",
+              "Cron.Start"
+            ]
+          },
+          {
+            "path": "github.com/pocketbase/pocketbase/tools/search",
+            "symbols": [
+              "Provider.Exec",
+              "Provider.ParseAndExec"
+            ]
+          },
+          {
+            "path": "github.com/pocketbase/pocketbase/plugins/jsvm",
+            "symbols": [
+              "BindApis",
+              "BindCore",
+              "BindDbx",
+              "BindFilepath",
+              "BindFilesystem",
+              "BindForms",
+              "BindHTTP",
+              "BindMails",
+              "BindOS",
+              "BindSecurity",
+              "MustRegister",
+              "Register",
+              "plugin.watchHooks"
+            ]
+          },
+          {
+            "path": "github.com/pocketbase/pocketbase/core",
+            "symbols": [
+              "AuthAlertConfig.Validate",
+              "AuthOrigin.CollectionRef",
+              "AuthOrigin.Created",
+              "AuthOrigin.Fingerprint",
+              "AuthOrigin.RecordRef",
+              "AuthOrigin.SetCollectionRef",
+              "AuthOrigin.SetFingerprint",
+              "AuthOrigin.SetRecordRef",
+              "AuthOrigin.Updated",
+              "AutodateField.Intercept",
+              "AutodateField.PrepareValue",
+              "AutodateField.ValidateSettings",
+              "BackupsConfig.Validate",
+              "BaseApp.AuxDelete",
+              "BaseApp.AuxDeleteWithContext",
+              "BaseApp.AuxHasTable",
+              "BaseApp.AuxRunInTransaction",
+              "BaseApp.AuxSave",
+              "BaseApp.AuxSaveNoValidate",
+              "BaseApp.AuxSaveNoValidateWithContext",
+              "BaseApp.AuxSaveWithContext",
+              "BaseApp.AuxVacuum",
+              "BaseApp.Bootstrap",
+              "BaseApp.CanAccessRecord",
+              "BaseApp.CountRecords",
+              "BaseApp.CreateBackup",
+              "BaseApp.CreateViewFields",
+              "BaseApp.Delete",
+              "BaseApp.DeleteAllAuthOriginsByRecord",
+              "BaseApp.DeleteAllExternalAuthsByRecord",
+              "BaseApp.DeleteAllMFAsByRecord",
+              "BaseApp.DeleteAllOTPsByRecord",
+              "BaseApp.DeleteExpiredMFAs",
+              "BaseApp.DeleteExpiredOTPs",
+              "BaseApp.DeleteOldLogs",
+              "BaseApp.DeleteTable",
+              "BaseApp.DeleteView",
+              "BaseApp.DeleteWithContext",
+              "BaseApp.DryRunView",
+              "BaseApp.ExpandRecord",
+              "BaseApp.ExpandRecords",
+              "BaseApp.FindAllAuthOriginsByCollection",
+              "BaseApp.FindAllAuthOriginsByRecord",
+              "BaseApp.FindAllCollections",
+              "BaseApp.FindAllExternalAuthsByCollection",
+              "BaseApp.FindAllExternalAuthsByRecord",
+              "BaseApp.FindAllMFAsByCollection",
+              "BaseApp.FindAllMFAsByRecord",
+              "BaseApp.FindAllOTPsByCollection",
+              "BaseApp.FindAllOTPsByRecord",
+              "BaseApp.FindAllRecords",
+              "BaseApp.FindAuthOriginById",
+              "BaseApp.FindAuthOriginByRecordAndFingerprint",
+              "BaseApp.FindAuthRecordByEmail",
+              "BaseApp.FindAuthRecordByToken",
+              "BaseApp.FindCachedCollectionByNameOrId",
+              "BaseApp.FindCachedCollectionReferences",
+              "BaseApp.FindCollectionByNameOrId",
+              "BaseApp.FindCollectionReferences",
+              "BaseApp.FindFirstExternalAuthByExpr",
+              "BaseApp.FindFirstRecordByData",
+              "BaseApp.FindFirstRecordByFilter",
+              "BaseApp.FindLogById",
+              "BaseApp.FindMFAById",
+              "BaseApp.FindOTPById",
+              "BaseApp.FindRecordById",
+              "BaseApp.FindRecordByViewFile",
+              "BaseApp.FindRecordsByFilter",
+              "BaseApp.FindRecordsByIds",
+              "BaseApp.HasTable",
+              "BaseApp.ImportCollections",
+              "BaseApp.ImportCollectionsByMarshaledJSON",
+              "BaseApp.IsCollectionNameUnique",
+              "BaseApp.LogsStats",
+              "BaseApp.NewBackupsFilesystem",
+              "BaseApp.NewFilesystem",
+              "BaseApp.RecordQuery",
+              "BaseApp.ReloadCachedCollections",
+              "BaseApp.ReloadSettings",
+              "BaseApp.ResetBootstrapState",
+              "BaseApp.Restart",
+              "BaseApp.RestoreBackup",
+              "BaseApp.RunAllMigrations",
+              "BaseApp.RunAppMigrations",
+              "BaseApp.RunInTransaction",
+              "BaseApp.RunSystemMigrations",
+              "BaseApp.Save",
+              "BaseApp.SaveNoValidate",
+              "BaseApp.SaveNoValidateWithContext",
+              "BaseApp.SaveView",
+              "BaseApp.SaveWithContext",
+              "BaseApp.SyncRecordTableSchema",
+              "BaseApp.TableColumns",
+              "BaseApp.TableIndexes",
+              "BaseApp.TableInfo",
+              "BaseApp.TruncateCollection",
+              "BaseApp.Vacuum",
+              "BaseApp.Validate",
+              "BaseApp.ValidateWithContext",
+              "BaseApp.initLogger",
+              "BatchConfig.Validate",
+              "BoolField.PrepareValue",
+              "BoolField.ValidateSettings",
+              "Collection.AddIndex",
+              "Collection.DBExport",
+              "Collection.GetIndex",
+              "Collection.MarshalJSON",
+              "Collection.PostScan",
+              "Collection.RemoveIndex",
+              "Collection.String",
+              "Collection.UnmarshalJSON",
+              "DateField.PrepareValue",
+              "DateField.ValidateSettings",
+              "DateField.ValidateValue",
+              "DefaultDBConnect",
+              "DefaultFieldHelpValidationRule",
+              "DefaultFieldIdValidationRule",
+              "DefaultFieldNameValidationRule",
+              "EditorField.PrepareValue",
+              "EditorField.ValidateSettings",
+              "EmailField.PrepareValue",
+              "EmailField.ValidateSettings",
+              "EmailField.ValidateValue",
+              "EmailTemplate.Resolve",
+              "EmailTemplate.Validate",
+              "ExternalAuth.CollectionRef",
+              "ExternalAuth.Created",
+              "ExternalAuth.Provider",
+              "ExternalAuth.ProviderId",
+              "ExternalAuth.RecordRef",
+              "ExternalAuth.SetCollectionRef",
+              "ExternalAuth.SetProvider",
+              "ExternalAuth.SetProviderId",
+              "ExternalAuth.SetRecordRef",
+              "ExternalAuth.Updated",
+              "FieldsList.Add",
+              "FieldsList.AddAt",
+              "FieldsList.AddMarshaledJSON",
+              "FieldsList.AddMarshaledJSONAt",
+              "FieldsList.Clone",
+              "FieldsList.MarshalJSON",
+              "FieldsList.Scan",
+              "FieldsList.String",
+              "FieldsList.UnmarshalJSON",
+              "FieldsList.Value",
+              "FileField.DriverValue",
+              "FileField.FindGetter",
+              "FileField.Intercept",
+              "FileField.PrepareValue",
+              "FileField.ValidateSettings",
+              "FileField.ValidateValue",
+              "GeoPointField.PrepareValue",
+              "GeoPointField.ValidateSettings",
+              "InternalRequest.Validate",
+              "JSONField.PrepareValue",
+              "JSONField.ValidateSettings",
+              "JSONField.ValidateValue",
+              "LogsConfig.Validate",
+              "MFA.CollectionRef",
+              "MFA.Created",
+              "MFA.HasExpired",
+              "MFA.Method",
+              "MFA.RecordRef",
+              "MFA.SetCollectionRef",
+              "MFA.SetMethod",
+              "MFA.SetRecordRef",
+              "MFA.Updated",
+              "MFAConfig.Validate",
+              "MetaConfig.Validate",
+              "MigrationsRunner.Down",
+              "MigrationsRunner.RemoveMissingAppliedMigrations",
+              "MigrationsRunner.Run",
+              "MigrationsRunner.Up",
+              "NewAuthCollection",
+              "NewAuthOrigin",
+              "NewBaseApp",
+              "NewBaseCollection",
+              "NewCollection",
+              "NewExternalAuth",
+              "NewFieldsList",
+              "NewMFA",
+              "NewOTP",
+              "NewRecord",
+              "NewRecordFieldResolver",
+              "NewViewCollection",
+              "NumberField.PrepareValue",
+              "NumberField.ValidateSettings",
+              "OAuth2Config.Validate",
+              "OAuth2ProviderConfig.InitProvider",
+              "OAuth2ProviderConfig.Validate",
+              "OTP.CollectionRef",
+              "OTP.Created",
+              "OTP.HasExpired",
+              "OTP.RecordRef",
+              "OTP.SentTo",
+              "OTP.SetCollectionRef",
+              "OTP.SetRecordRef",
+              "OTP.SetSentTo",
+              "OTP.Updated",
+              "OTPConfig.Validate",
+              "PasswordAuthConfig.Validate",
+              "PasswordField.Intercept",
+              "PasswordField.PrepareValue",
+              "PasswordField.ValidateSettings",
+              "PasswordField.ValidateValue",
+              "PasswordFieldValue.Validate",
+              "RateLimitRule.String",
+              "RateLimitRule.Validate",
+              "RateLimitsConfig.MarshalJSON",
+              "RateLimitsConfig.Validate",
+              "Record.BaseFilesPath",
+              "Record.Clone",
+              "Record.DBExport",
+              "Record.Email",
+              "Record.EmailVisibility",
+              "Record.FieldsData",
+              "Record.FindFileFieldByFile",
+              "Record.Fresh",
+              "Record.Get",
+              "Record.GetBool",
+              "Record.GetDateTime",
+              "Record.GetFloat",
+              "Record.GetGeoPoint",
+              "Record.GetInt",
+              "Record.GetString",
+              "Record.GetStringSlice",
+              "Record.GetUnsavedFiles",
+              "Record.GetUploadedFiles",
+              "Record.Load",
+              "Record.MarshalJSON",
+              "Record.NewAuthToken",
+              "Record.NewEmailChangeToken",
+              "Record.NewFileToken",
+              "Record.NewPasswordResetToken",
+              "Record.NewStaticAuthToken",
+              "Record.NewVerificationToken",
+              "Record.Original",
+              "Record.PostScan",
+              "Record.PublicExport",
+              "Record.RefreshTokenKey",
+              "Record.ReplaceModifiers",
+              "Record.Set",
+              "Record.SetEmail",
+              "Record.SetEmailVisibility",
+              "Record.SetIfFieldExists",
+              "Record.SetPassword",
+              "Record.SetRandomPassword",
+              "Record.SetRaw",
+              "Record.SetTokenKey",
+              "Record.SetVerified",
+              "Record.TokenKey",
+              "Record.UnmarshalJSON",
+              "Record.UnmarshalJSONField",
+              "Record.ValidatePassword",
+              "Record.Verified",
+              "RecordFieldResolver.Resolve",
+              "RecordFieldResolver.UpdateQuery",
+              "RelationField.DriverValue",
+              "RelationField.PrepareValue",
+              "RelationField.ValidateSettings",
+              "RelationField.ValidateValue",
+              "RequestEvent.RealIP",
+              "RequestEvent.RequestInfo",
+              "RequestInfo.Clone",
+              "S3Config.Validate",
+              "SMTPConfig.MarshalJSON",
+              "SMTPConfig.Validate",
+              "SelectField.DriverValue",
+              "SelectField.PrepareValue",
+              "SelectField.ValidateSettings",
+              "SelectField.ValidateValue",
+              "Settings.Clone",
+              "Settings.DBExport",
+              "Settings.MarshalJSON",
+              "Settings.Merge",
+              "Settings.PostValidate",
+              "Settings.String",
+              "TextField.Intercept",
+              "TextField.PrepareValue",
+              "TextField.ValidatePlainValue",
+              "TextField.ValidateSettings",
+              "TextField.ValidateValue",
+              "TokenConfig.Validate",
+              "TrustedProxyConfig.MarshalJSON",
+              "URLField.PrepareValue",
+              "URLField.ValidateSettings",
+              "URLField.ValidateValue",
+              "createNotifyDirWatcher",
+              "dualDBBuilder.AddColumn",
+              "dualDBBuilder.AddForeignKey",
+              "dualDBBuilder.AddPrimaryKey",
+              "dualDBBuilder.AlterColumn",
+              "dualDBBuilder.CreateIndex",
+              "dualDBBuilder.CreateTable",
+              "dualDBBuilder.CreateUniqueIndex",
+              "dualDBBuilder.Delete",
+              "dualDBBuilder.DropColumn",
+              "dualDBBuilder.DropForeignKey",
+              "dualDBBuilder.DropIndex",
+              "dualDBBuilder.DropPrimaryKey",
+              "dualDBBuilder.DropTable",
+              "dualDBBuilder.GeneratePlaceholder",
+              "dualDBBuilder.Insert",
+              "dualDBBuilder.Model",
+              "dualDBBuilder.NewQuery",
+              "dualDBBuilder.RenameColumn",
+              "dualDBBuilder.RenameTable",
+              "dualDBBuilder.TruncateTable",
+              "dualDBBuilder.Update",
+              "dualDBBuilder.Upsert",
+              "fieldWithType.UnmarshalJSON",
+              "replaceWithExpression.Build"
+            ]
+          },
+          {
+            "path": "github.com/pocketbase/pocketbase/daos",
+            "symbols": [
+              "Dao.parseQueryToFields"
+            ]
+          },
+          {
+            "path": "github.com/pocketbase/pocketbase/tools/filesystem/internal/s3lite",
+            "symbols": [
+              "writer.open"
+            ]
+          },
+          {
+            "path": "github.com/pocketbase/pocketbase/apis",
+            "symbols": [
+              "backupApi.restore",
+              "batchProcessor.Process",
+              "realtimeBroadcastDryCacheKey",
+              "realtimeBroadcastRecord",
+              "realtimeUnsetClientsAuthByCollection",
+              "realtimeUnsetClientsAuthByRecordModelOrProxy",
+              "realtimeUnsetDryCacheKey",
+              "realtimeUpdateClientsAuth"
+            ]
+          },
+          {
+            "path": "github.com/pocketbase/pocketbase",
+            "symbols": [
+              "New",
+              "NewWithConfig",
+              "PocketBase.Execute",
+              "PocketBase.Start",
+              "coloredWriter.Write"
+            ]
+          },
+          {
+            "path": "github.com/pocketbase/pocketbase/tools/filesystem/internal/s3blob",
+            "symbols": [
+              "writer.Close",
+              "writer.Write",
+              "writer.open"
+            ]
+          },
+          {
+            "path": "github.com/pocketbase/pocketbase/tools/filesystem/internal/s3blob/s3",
+            "symbols": [
+              "Uploader.Upload",
+              "Uploader.multipartUpload"
+            ]
+          }
+        ]
+      }
+    }
+  ],
+  "references": [
+    {
+      "type": "ADVISORY",
+      "url": "https://github.com/pocketbase/pocketbase/security/advisories/GHSA-84vh-m24q-wjjx"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/pocketbase/pocketbase/commit/30b4184305904fae0d1b78216c4e3cc34700b220"
+    },
+    {
+      "type": "FIX",
+      "url": "https://github.com/pocketbase/pocketbase/commit/f1618ee59b6d1c0308bb474c827a2b1f24b12a95"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/pocketbase/pocketbase/discussions/7762"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/pocketbase/pocketbase/releases/tag/v0.22.48"
+    },
+    {
+      "type": "WEB",
+      "url": "https://github.com/pocketbase/pocketbase/releases/tag/v0.39.7"
+    }
+  ],
+  "database_specific": {
+    "url": "https://pkg.go.dev/vuln/GO-2026-6489",
+    "review_status": "REVIEWED"
+  }
+}
\ No newline at end of file
diff --git a/data/reports/GO-2026-6489.yaml b/data/reports/GO-2026-6489.yaml
new file mode 100644
index 0000000..3c71b92
--- /dev/null
+++ b/data/reports/GO-2026-6489.yaml
@@ -0,0 +1,406 @@
+id: GO-2026-6489
+modules:
+    - module: github.com/pocketbase/pocketbase
+      versions:
+        - fixed: 0.22.48
+        - introduced: 0.23.0
+        - fixed: 0.39.7
+      vulnerable_at: 0.39.6
+      packages:
+        - package: github.com/pocketbase/pocketbase/tools/cron
+          symbols:
+            - Cron.Start
+          derived_symbols:
+            - Cron.SetInterval
+        - package: github.com/pocketbase/pocketbase/tools/search
+          symbols:
+            - Provider.Exec
+          derived_symbols:
+            - Provider.ParseAndExec
+        - package: github.com/pocketbase/pocketbase/plugins/jsvm
+          symbols:
+            - plugin.watchHooks
+          derived_symbols:
+            - BindApis
+            - BindCore
+            - BindDbx
+            - BindFilepath
+            - BindFilesystem
+            - BindForms
+            - BindHTTP
+            - BindMails
+            - BindOS
+            - BindSecurity
+            - MustRegister
+            - Register
+        - package: github.com/pocketbase/pocketbase/core
+          symbols:
+            - BaseApp.initLogger
+            - createNotifyDirWatcher
+          derived_symbols:
+            - AuthAlertConfig.Validate
+            - AuthOrigin.CollectionRef
+            - AuthOrigin.Created
+            - AuthOrigin.Fingerprint
+            - AuthOrigin.RecordRef
+            - AuthOrigin.SetCollectionRef
+            - AuthOrigin.SetFingerprint
+            - AuthOrigin.SetRecordRef
+            - AuthOrigin.Updated
+            - AutodateField.Intercept
+            - AutodateField.PrepareValue
+            - AutodateField.ValidateSettings
+            - BackupsConfig.Validate
+            - BaseApp.AuxDelete
+            - BaseApp.AuxDeleteWithContext
+            - BaseApp.AuxHasTable
+            - BaseApp.AuxRunInTransaction
+            - BaseApp.AuxSave
+            - BaseApp.AuxSaveNoValidate
+            - BaseApp.AuxSaveNoValidateWithContext
+            - BaseApp.AuxSaveWithContext
+            - BaseApp.AuxVacuum
+            - BaseApp.Bootstrap
+            - BaseApp.CanAccessRecord
+            - BaseApp.CountRecords
+            - BaseApp.CreateBackup
+            - BaseApp.CreateViewFields
+            - BaseApp.Delete
+            - BaseApp.DeleteAllAuthOriginsByRecord
+            - BaseApp.DeleteAllExternalAuthsByRecord
+            - BaseApp.DeleteAllMFAsByRecord
+            - BaseApp.DeleteAllOTPsByRecord
+            - BaseApp.DeleteExpiredMFAs
+            - BaseApp.DeleteExpiredOTPs
+            - BaseApp.DeleteOldLogs
+            - BaseApp.DeleteTable
+            - BaseApp.DeleteView
+            - BaseApp.DeleteWithContext
+            - BaseApp.DryRunView
+            - BaseApp.ExpandRecord
+            - BaseApp.ExpandRecords
+            - BaseApp.FindAllAuthOriginsByCollection
+            - BaseApp.FindAllAuthOriginsByRecord
+            - BaseApp.FindAllCollections
+            - BaseApp.FindAllExternalAuthsByCollection
+            - BaseApp.FindAllExternalAuthsByRecord
+            - BaseApp.FindAllMFAsByCollection
+            - BaseApp.FindAllMFAsByRecord
+            - BaseApp.FindAllOTPsByCollection
+            - BaseApp.FindAllOTPsByRecord
+            - BaseApp.FindAllRecords
+            - BaseApp.FindAuthOriginById
+            - BaseApp.FindAuthOriginByRecordAndFingerprint
+            - BaseApp.FindAuthRecordByEmail
+            - BaseApp.FindAuthRecordByToken
+            - BaseApp.FindCachedCollectionByNameOrId
+            - BaseApp.FindCachedCollectionReferences
+            - BaseApp.FindCollectionByNameOrId
+            - BaseApp.FindCollectionReferences
+            - BaseApp.FindFirstExternalAuthByExpr
+            - BaseApp.FindFirstRecordByData
+            - BaseApp.FindFirstRecordByFilter
+            - BaseApp.FindLogById
+            - BaseApp.FindMFAById
+            - BaseApp.FindOTPById
+            - BaseApp.FindRecordById
+            - BaseApp.FindRecordByViewFile
+            - BaseApp.FindRecordsByFilter
+            - BaseApp.FindRecordsByIds
+            - BaseApp.HasTable
+            - BaseApp.ImportCollections
+            - BaseApp.ImportCollectionsByMarshaledJSON
+            - BaseApp.IsCollectionNameUnique
+            - BaseApp.LogsStats
+            - BaseApp.NewBackupsFilesystem
+            - BaseApp.NewFilesystem
+            - BaseApp.RecordQuery
+            - BaseApp.ReloadCachedCollections
+            - BaseApp.ReloadSettings
+            - BaseApp.ResetBootstrapState
+            - BaseApp.Restart
+            - BaseApp.RestoreBackup
+            - BaseApp.RunAllMigrations
+            - BaseApp.RunAppMigrations
+            - BaseApp.RunInTransaction
+            - BaseApp.RunSystemMigrations
+            - BaseApp.Save
+            - BaseApp.SaveNoValidate
+            - BaseApp.SaveNoValidateWithContext
+            - BaseApp.SaveView
+            - BaseApp.SaveWithContext
+            - BaseApp.SyncRecordTableSchema
+            - BaseApp.TableColumns
+            - BaseApp.TableIndexes
+            - BaseApp.TableInfo
+            - BaseApp.TruncateCollection
+            - BaseApp.Vacuum
+            - BaseApp.Validate
+            - BaseApp.ValidateWithContext
+            - BatchConfig.Validate
+            - BoolField.PrepareValue
+            - BoolField.ValidateSettings
+            - Collection.AddIndex
+            - Collection.DBExport
+            - Collection.GetIndex
+            - Collection.MarshalJSON
+            - Collection.PostScan
+            - Collection.RemoveIndex
+            - Collection.String
+            - Collection.UnmarshalJSON
+            - DateField.PrepareValue
+            - DateField.ValidateSettings
+            - DateField.ValidateValue
+            - DefaultDBConnect
+            - DefaultFieldHelpValidationRule
+            - DefaultFieldIdValidationRule
+            - DefaultFieldNameValidationRule
+            - EditorField.PrepareValue
+            - EditorField.ValidateSettings
+            - EmailField.PrepareValue
+            - EmailField.ValidateSettings
+            - EmailField.ValidateValue
+            - EmailTemplate.Resolve
+            - EmailTemplate.Validate
+            - ExternalAuth.CollectionRef
+            - ExternalAuth.Created
+            - ExternalAuth.Provider
+            - ExternalAuth.ProviderId
+            - ExternalAuth.RecordRef
+            - ExternalAuth.SetCollectionRef
+            - ExternalAuth.SetProvider
+            - ExternalAuth.SetProviderId
+            - ExternalAuth.SetRecordRef
+            - ExternalAuth.Updated
+            - FieldsList.Add
+            - FieldsList.AddAt
+            - FieldsList.AddMarshaledJSON
+            - FieldsList.AddMarshaledJSONAt
+            - FieldsList.Clone
+            - FieldsList.MarshalJSON
+            - FieldsList.Scan
+            - FieldsList.String
+            - FieldsList.UnmarshalJSON
+            - FieldsList.Value
+            - FileField.DriverValue
+            - FileField.FindGetter
+            - FileField.Intercept
+            - FileField.PrepareValue
+            - FileField.ValidateSettings
+            - FileField.ValidateValue
+            - GeoPointField.PrepareValue
+            - GeoPointField.ValidateSettings
+            - InternalRequest.Validate
+            - JSONField.PrepareValue
+            - JSONField.ValidateSettings
+            - JSONField.ValidateValue
+            - LogsConfig.Validate
+            - MFA.CollectionRef
+            - MFA.Created
+            - MFA.HasExpired
+            - MFA.Method
+            - MFA.RecordRef
+            - MFA.SetCollectionRef
+            - MFA.SetMethod
+            - MFA.SetRecordRef
+            - MFA.Updated
+            - MFAConfig.Validate
+            - MetaConfig.Validate
+            - MigrationsRunner.Down
+            - MigrationsRunner.RemoveMissingAppliedMigrations
+            - MigrationsRunner.Run
+            - MigrationsRunner.Up
+            - NewAuthCollection
+            - NewAuthOrigin
+            - NewBaseApp
+            - NewBaseCollection
+            - NewCollection
+            - NewExternalAuth
+            - NewFieldsList
+            - NewMFA
+            - NewOTP
+            - NewRecord
+            - NewRecordFieldResolver
+            - NewViewCollection
+            - NumberField.PrepareValue
+            - NumberField.ValidateSettings
+            - OAuth2Config.Validate
+            - OAuth2ProviderConfig.InitProvider
+            - OAuth2ProviderConfig.Validate
+            - OTP.CollectionRef
+            - OTP.Created
+            - OTP.HasExpired
+            - OTP.RecordRef
+            - OTP.SentTo
+            - OTP.SetCollectionRef
+            - OTP.SetRecordRef
+            - OTP.SetSentTo
+            - OTP.Updated
+            - OTPConfig.Validate
+            - PasswordAuthConfig.Validate
+            - PasswordField.Intercept
+            - PasswordField.PrepareValue
+            - PasswordField.ValidateSettings
+            - PasswordField.ValidateValue
+            - PasswordFieldValue.Validate
+            - RateLimitRule.String
+            - RateLimitRule.Validate
+            - RateLimitsConfig.MarshalJSON
+            - RateLimitsConfig.Validate
+            - Record.BaseFilesPath
+            - Record.Clone
+            - Record.DBExport
+            - Record.Email
+            - Record.EmailVisibility
+            - Record.FieldsData
+            - Record.FindFileFieldByFile
+            - Record.Fresh
+            - Record.Get
+            - Record.GetBool
+            - Record.GetDateTime
+            - Record.GetFloat
+            - Record.GetGeoPoint
+            - Record.GetInt
+            - Record.GetString
+            - Record.GetStringSlice
+            - Record.GetUnsavedFiles
+            - Record.GetUploadedFiles
+            - Record.Load
+            - Record.MarshalJSON
+            - Record.NewAuthToken
+            - Record.NewEmailChangeToken
+            - Record.NewFileToken
+            - Record.NewPasswordResetToken
+            - Record.NewStaticAuthToken
+            - Record.NewVerificationToken
+            - Record.Original
+            - Record.PostScan
+            - Record.PublicExport
+            - Record.RefreshTokenKey
+            - Record.ReplaceModifiers
+            - Record.Set
+            - Record.SetEmail
+            - Record.SetEmailVisibility
+            - Record.SetIfFieldExists
+            - Record.SetPassword
+            - Record.SetRandomPassword
+            - Record.SetRaw
+            - Record.SetTokenKey
+            - Record.SetVerified
+            - Record.TokenKey
+            - Record.UnmarshalJSON
+            - Record.UnmarshalJSONField
+            - Record.ValidatePassword
+            - Record.Verified
+            - RecordFieldResolver.Resolve
+            - RecordFieldResolver.UpdateQuery
+            - RelationField.DriverValue
+            - RelationField.PrepareValue
+            - RelationField.ValidateSettings
+            - RelationField.ValidateValue
+            - RequestEvent.RealIP
+            - RequestEvent.RequestInfo
+            - RequestInfo.Clone
+            - S3Config.Validate
+            - SMTPConfig.MarshalJSON
+            - SMTPConfig.Validate
+            - SelectField.DriverValue
+            - SelectField.PrepareValue
+            - SelectField.ValidateSettings
+            - SelectField.ValidateValue
+            - Settings.Clone
+            - Settings.DBExport
+            - Settings.MarshalJSON
+            - Settings.Merge
+            - Settings.PostValidate
+            - Settings.String
+            - TextField.Intercept
+            - TextField.PrepareValue
+            - TextField.ValidatePlainValue
+            - TextField.ValidateSettings
+            - TextField.ValidateValue
+            - TokenConfig.Validate
+            - TrustedProxyConfig.MarshalJSON
+            - URLField.PrepareValue
+            - URLField.ValidateSettings
+            - URLField.ValidateValue
+            - dualDBBuilder.AddColumn
+            - dualDBBuilder.AddForeignKey
+            - dualDBBuilder.AddPrimaryKey
+            - dualDBBuilder.AlterColumn
+            - dualDBBuilder.CreateIndex
+            - dualDBBuilder.CreateTable
+            - dualDBBuilder.CreateUniqueIndex
+            - dualDBBuilder.Delete
+            - dualDBBuilder.DropColumn
+            - dualDBBuilder.DropForeignKey
+            - dualDBBuilder.DropIndex
+            - dualDBBuilder.DropPrimaryKey
+            - dualDBBuilder.DropTable
+            - dualDBBuilder.GeneratePlaceholder
+            - dualDBBuilder.Insert
+            - dualDBBuilder.Model
+            - dualDBBuilder.NewQuery
+            - dualDBBuilder.RenameColumn
+            - dualDBBuilder.RenameTable
+            - dualDBBuilder.TruncateTable
+            - dualDBBuilder.Update
+            - dualDBBuilder.Upsert
+            - fieldWithType.UnmarshalJSON
+            - replaceWithExpression.Build
+        - package: github.com/pocketbase/pocketbase/daos
+          symbols:
+            - Dao.parseQueryToFields
+          skip_fix: build errors during static analysis
+        - package: github.com/pocketbase/pocketbase/tools/filesystem/internal/s3lite
+          symbols:
+            - writer.open
+          skip_fix: build errors during static analysis
+        - package: github.com/pocketbase/pocketbase/apis
+          symbols:
+            - backupApi.restore
+            - realtimeUnsetClientsAuthByCollection
+            - realtimeBroadcastRecord
+            - realtimeUnsetClientsAuthByRecordModelOrProxy
+            - batchProcessor.Process
+            - realtimeUpdateClientsAuth
+            - realtimeBroadcastDryCacheKey
+            - realtimeUnsetDryCacheKey
+          skip_fix: build errors during static analysis
+        - package: github.com/pocketbase/pocketbase
+          symbols:
+            - PocketBase.Execute
+          derived_symbols:
+            - New
+            - NewWithConfig
+            - PocketBase.Start
+            - coloredWriter.Write
+        - package: github.com/pocketbase/pocketbase/tools/filesystem/internal/s3blob
+          symbols:
+            - writer.open
+          derived_symbols:
+            - writer.Close
+            - writer.Write
+        - package: github.com/pocketbase/pocketbase/tools/filesystem/internal/s3blob/s3
+          symbols:
+            - Uploader.multipartUpload
+          derived_symbols:
+            - Uploader.Upload
+summary: |-
+    Pocketbase: Unhandled panic in worker goroutines in
+    github.com/pocketbase/pocketbase
+cves:
+    - CVE-2026-82410
+ghsas:
+    - GHSA-84vh-m24q-wjjx
+references:
+    - advisory: https://github.com/pocketbase/pocketbase/security/advisories/GHSA-84vh-m24q-wjjx
+    - fix: https://github.com/pocketbase/pocketbase/commit/30b4184305904fae0d1b78216c4e3cc34700b220
+    - fix: https://github.com/pocketbase/pocketbase/commit/f1618ee59b6d1c0308bb474c827a2b1f24b12a95
+    - web: https://github.com/pocketbase/pocketbase/discussions/7762
+    - web: https://github.com/pocketbase/pocketbase/releases/tag/v0.22.48
+    - web: https://github.com/pocketbase/pocketbase/releases/tag/v0.39.7
+source:
+    id: GHSA-84vh-m24q-wjjx
+    created: 2026-10-05T10:40:49.642045-04:00
+review_status: REVIEWED