Netmaker Vulnerable to Denial of Service via Server Shutdown Endpoint
Description
Published to the GitHub Advisory Database
Mar 4, 2026
Reviewed
Mar 4, 2026
Published by the National Vulnerability Database
Mar 7, 2026
Last updated
Mar 9, 2026
The /api/server/shutdown endpoint allows termination of the Netmaker server process via syscall.SIGINT. This allows any user to repeatedly shut down the server, causing cyclic denial of service with approximately 3-second restart intervals.
References