GHSA-hmqr-wjmj-376c

Suggest an improvement
Source
https://github.com/advisories/GHSA-hmqr-wjmj-376c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hmqr-wjmj-376c/GHSA-hmqr-wjmj-376c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hmqr-wjmj-376c
Aliases
Published
2026-03-09T17:27:46Z
Modified
2026-03-23T04:56:26Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Netmaker has Insufficient Authorization in Host Token Verification
Details

The Authorise middleware in Netmaker incorrectly validates host JWT tokens. When a route permits host authentication (hostAllowed=true), a valid host token bypasses all subsequent authorisation checks without verifying that the host is authorised to access the specific requested resource. Any entity possessing knowledge of object identifiers (node IDs, host IDs) can craft a request with an arbitrary valid host token to access, modify, or delete resources belonging to other hosts. Affected endpoints include node info retrieval, host deletion, MQTT signal transmission, fallback host updates, and failover operations.

Credits Artem Danilov (Positive Technologies)

Database specific
{
    "cwe_ids":  [
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-09T17:27:46Z",
    "nvd_published_at":  "2026-03-07T16:15:54Z",
    "severity":  "HIGH"
}
References

Affected packages

Go / github.com/gravitl/netmaker

Package

Name
github.com/gravitl/netmaker
View open source insights on deps.dev
Purl
pkg:golang/github.com/gravitl/netmaker

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hmqr-wjmj-376c/GHSA-hmqr-wjmj-376c.json"