Vulnerability GO-2026-5588
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 months ago
June 25, 2026 at 10:34 PM UTC
Netmaker does not verify JWT signatures for host tokens in github.com/gravitl/netmaker
v0.5.5 - v1.4.0
v0.5.5 - v1.4.0
Summary
Netmaker does not verify JWT signatures for host tokens in github.com/gravitl/netmaker
Details
Netmaker does not verify JWT signatures for host tokens in github.com/gravitl/netmaker
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 hours ago
Netmaker has a boolean‑based SQL Injection
v0.5.5 - v1.4.0 GHSA-r8cr-4f9w-7r75
v0.5.5 - v1.4.0 GHSA-r8cr-4f9w-7r75
High Risk
4 months ago
Netmaker does not verify JWT signatures for host tokens
v0.5.5 - v1.4.0 GHSA-qpv2-rwc8-c993
v0.5.5 - v1.4.0 GHSA-qpv2-rwc8-c993
Unknown
6 months ago
Netmaker: Service User with Network Access Can Access config files with WireGuard Private Keys in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-4651
v0.5.5 - v1.4.0 GO-2026-4651
Unknown
6 months ago
Netmaker has Privilege Escalation from Admin to Super-Admin via User Update in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-4654
v0.5.5 - v1.4.0 GO-2026-4654
Unknown
6 months ago
Netmaker has Insufficient Authorization in Host Token Verification in github.com/gravitl/netmaker
v0.5.5 - v1.4.0 GO-2026-4655
v0.5.5 - v1.4.0 GO-2026-4655
Impacted packages
Timeline
Published
2 months ago
June 25, 2026 at 10:34 PM UTC
Last Modified
2 months ago
June 25, 2026 at 11:01 PM UTC