CVE-2026-29771

EPSS 0.02%

Netmaker Vulnerable to Denial of Service via Server Shutdown Endpoint

Published: 3/4/2026Modified: 3/23/2026
Also known as:GHSA-rhr9-hgcm-x289GO-2026-4608

Description

The /api/server/shutdown endpoint allows termination of the Netmaker server process via syscall.SIGINT. This allows any user to repeatedly shut down the server, causing cyclic denial of service with approximately 3-second restart intervals.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References (3)