{"id":"GO-2026-5457","summary":"Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS in github.com/basekick-labs/arc","details":"Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS in github.com/basekick-labs/arc","aliases":["CVE-2026-48050","GHSA-j93g-rp6m-j32m"],"modified":"2026-06-25T23:01:18.241165504Z","published":"2026-06-25T22:34:31Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5457","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/Basekick-Labs/arc/security/advisories/GHSA-j93g-rp6m-j32m"},{"type":"WEB","url":"https://github.com/Basekick-Labs/arc/commit/32a4091fb949f9cf060cdd804a07f6450dc426a8"},{"type":"WEB","url":"https://github.com/Basekick-Labs/arc/releases/tag/v26.06.1"}],"affected":[{"package":{"name":"github.com/basekick-labs/arc","ecosystem":"Go","purl":"pkg:golang/github.com/basekick-labs/arc"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260520170331-32a4091fb949"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5457.json"}}],"schema_version":"1.7.5"}