Vulnerability GO-2026-4651
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 months ago
March 11, 2026 at 04:00 PM UTC
Netmaker: Service User with Network Access Can Access config files with WireGuard Private Keys in github.com/gravitl/netmaker
v0.5.5 - v1.4.0
v0.5.5 - v1.4.0
Summary
Netmaker: Service User with Network Access Can Access config files with WireGuard Private Keys in github.com/gravitl/netmaker
Details
Netmaker: Service User with Network Access Can Access config files with WireGuard Private Keys in github.com/gravitl/netmaker
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 hours ago
Netmaker has a boolean‑based SQL Injection
v0.5.5 - v1.4.0 GHSA-r8cr-4f9w-7r75
v0.5.5 - v1.4.0 GHSA-r8cr-4f9w-7r75
Unknown
2 months ago
Netmaker does not verify JWT signatures for host tokens in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-5588
v0.5.5 - v1.4.0 GO-2026-5588
High Risk
4 months ago
Netmaker does not verify JWT signatures for host tokens
v0.5.5 - v1.4.0 GHSA-qpv2-rwc8-c993
v0.5.5 - v1.4.0 GHSA-qpv2-rwc8-c993
Unknown
6 months ago
Netmaker has Privilege Escalation from Admin to Super-Admin via User Update in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-4654
v0.5.5 - v1.4.0 GO-2026-4654
Unknown
6 months ago
Netmaker has Insufficient Authorization in Host Token Verification in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-4655
v0.5.5 - v1.4.0 GO-2026-4655
Impacted packages
Timeline
Published
6 months ago
March 11, 2026 at 04:00 PM UTC
Last Modified
5 months ago
March 23, 2026 at 04:52 AM UTC