Dependency scanning
Check whether github.com/gravitl/netmaker is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-38651
Netmaker does not verify JWT signatures for host tokens
CVE-2026-38651
Netmaker does not verify JWT signatures for host tokens in github.com/gravitl/netmaker
CVE-2022-23650
Use of Hard-coded Cryptographic Key in Netmaker
CVE-2023-32077
Netmaker has Hardcoded DNS Secret Key
CVE-2026-29194
Netmaker has Insufficient Authorization in Host Token Verification
CVE-2026-29195
Netmaker has Privilege Escalation from Admin to Super-Admin via User Update
CVE-2026-29771
Netmaker Vulnerable to Denial of Service via Server Shutdown Endpoint
CVE-2026-29196
Netmaker: Service User with Network Access Can Access config files with WireGuard Private Keys
CVE-2026-29771
Netmaker Vulnerable to Denial of Service via Server Shutdown Endpoint in github.com/gravitl/netmaker
CVE-2026-29194
Netmaker has Insufficient Authorization in Host Token Verification in github.com/gravitl/netmaker
CVE-2026-29195
Netmaker has Privilege Escalation from Admin to Super-Admin via User Update in github.com/gravitl/netmaker
CVE-2026-29196
Netmaker: Service User with Network Access Can Access config files with WireGuard Private Keys in github.com/gravitl/netmaker
CVE-2023-32077
Netmaker has Hardcoded DNS Secret Key in github.com/gravitl/netmaker
CVE-2023-32078
Netmaker IDOR Allows User to Update Other User's Password in github.com/gravitl/netmaker
CVE-2023-32079
Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User in github.com/gravitl/netmaker
CVE-2022-36110
Netmaker vulnerable to Insufficient Granularity of Access Control in github.com/gravitl/netmaker
CVE-2022-0664
Use of Hard-coded Cryptographic Key in Netmaker in github.com/gravitl/netmaker
CVE-2022-23650
Use of Hard-coded Cryptographic Key in Netmaker in github.com/gravitl/netmaker
CVE-2022-36110
Netmaker vulnerable to Insufficient Granularity of Access Control
CVE-2022-0664
Use of Hard-coded Cryptographic Key in Netmaker
CVE-2023-32078
Netmaker IDOR Allows User to Update Other User's Password
CVE-2023-32079
Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes