CVE-2026-29771

Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of the Netmaker server process via syscall.SIGINT. This allows any user to repeatedly shut down the server, causing cyclic denial of service with approximately 3-second restart intervals. This issue has been patched in version 1.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gravitl:netmaker:*:*:*:*:*:*:*:*

History

12 Mar 2026, 13:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
Summary
  • (es) Netmaker crea redes con WireGuard. Antes de la versión 1.2.0, el endpoint /API/servidor/shutdown permite la terminación del proceso del servidor Netmaker a través de syscall.SIGINT. Esto permite a cualquier usuario apagar repetidamente el servidor, causando una denegación de servicio cíclica con intervalos de reinicio de aproximadamente 3 segundos. Este problema ha sido parcheado en la versión 1.2.0.
References () https://github.com/gravitl/netmaker/security/advisories/GHSA-rhr9-hgcm-x289 - () https://github.com/gravitl/netmaker/security/advisories/GHSA-rhr9-hgcm-x289 - Vendor Advisory
First Time Gravitl netmaker
Gravitl
CPE cpe:2.3:a:gravitl:netmaker:*:*:*:*:*:*:*:*

07 Mar 2026, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 16:15

Updated : 2026-03-12 13:58


NVD link : CVE-2026-29771

Mitre link : CVE-2026-29771

CVE.ORG link : CVE-2026-29771


JSON object : View

Products Affected

gravitl

  • netmaker
CWE
CWE-404

Improper Resource Shutdown or Release