{"id":"CVE-2026-29771","aliases":["GHSA-rhr9-hgcm-x289","GO-2026-4608"],"url":"https://o3.security/vulnerability/CVE-2026-29771","summary":"Netmaker: Denial of Service via Server Shutdown Endpoint","details":"Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of the Netmaker server process via syscall.SIGINT. This allows any user to repeatedly shut down the server, causing cyclic denial of service with approximately 3-second restart intervals. This issue has been patched in version 1.2.0.","published":"2026-03-07T15:14:38.361Z","modified":"2026-08-07T11:50:51.622868973Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/gravitl/netmaker","fixedVersion":"1.2.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29771.json"},{"type":"ADVISORY","url":"https://github.com/gravitl/netmaker/security/advisories/GHSA-rhr9-hgcm-x289"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29771"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:51.622868973Z"}}