PatchSiren

pocketbase CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pocketbase CVE published 2026-09-17

CVE-2026-82410

The CVE Program has published a record for a vulnerability in Pocketbase, a Go package, which could lead to unhandled panic in worker goroutines. The NVD entry is currently unknown. The vulnerability was reported by osv_dev via a source item. There are multiple references to source code changes and discussions related to this issue. Defenders should assess the potential impact and verify exposure of syste [truncated]

MEDIUM pocketbase CVE published 2026-05-12

CVE-2026-44166

PocketBase versions prior to 0.22.42 and 0.37.4 contain an authentication bypass vulnerability in their OAuth2 user linking mechanism. An attacker who knows a victim's email address can pre-create an unverified PocketBase user account by authenticating with one OAuth2 provider (e.g., Provider A). When the legitimate victim later signs up or is invited using a different OAuth2 provider (Provider B), Pocket [truncated]