CVE-2026-29771
EPSS 0.02%Netmaker Vulnerable to Denial of Service via Server Shutdown Endpoint
Published: 3/4/2026Modified: 3/23/2026
Description
The /api/server/shutdown endpoint allows termination of the Netmaker server process via syscall.SIGINT. This allows any user to repeatedly shut down the server, causing cyclic denial of service with approximately 3-second restart intervals.
Affected packages (2)
- Go/github.com/gravitl/netmakerfrom 0, < 1.2.0
- Go/github.com/gravitl/netmakerfrom 0, < 1.2.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |