criticalCVSS 9.8Vulnerability

GHSA-2hp7-65r3-wv54

## Summary The `--address` CLI flag (and `NORNICDB_ADDRESS` / `server.host` config key) is plumbed through to the HTTP server correctly but **never reaches the Bolt server config**. The Bolt listener therefore always binds to the wildcard address (all interfaces), regardless of what the user configures. On a LAN, this exposes the graph database — with its default `admin:password` credentials — to any device sharing the network. ## Version - `nornicdb v1.0.39` - Built from commit `afe7c9d` on `main` - Platform: macOS (darwin 25.4.0, arm64) ## Reproduction ``` $ nornicdb serve --address 127.0.0.1 --bolt-port 7687 --http-port 7474 ... ``` Output claims Bolt is on localhost: ``` Bolt server listening on bolt://localhost:7687 ``` But the actual socket: ``` $ netstat -an -p tcp | grep 7687 tcp46 0 0 *.7687 *.* LISTEN $ lsof -iTCP:7687 -sTCP:LISTEN -n -P nornicdb ... IPv6 ... TCP *:7687 (LISTEN) ``` HTTP port is correctly bound: ``` tcp4 127.0.0.1.7474 *.* LISTEN ``` Reachable from another host on the LAN: ``` $ nc -z 192.168.x.y 7687 Connection to 192.168.x.y port 7687 [tcp/*] succeeded! ``` Setting `NORNICDB_BOLT_ADDRESS=127.0.0.1` or `server.host: "127.0.0.1"` in `config.yaml` has **no effect** on the Bolt listener. ## Root Cause In `pkg/bolt/server.go:774-776`: ```go func (s *Server) ListenAndServe() error { addr := fmt.Sprintf(":%d", s.config.Port) listener, err := net.Listen("tcp", addr) ... } ``` `bolt.Config` (line 474) has no `Host`/`Address`/`Addr` field — only `Port`. The CLI flag `--address` is stored in a local variable in `cmd/nornicdb/main.go:80` and used to format user-facing log output (line 637–644), but is never copied into `boltConfig` at line 600–609 when Bolt is initialized. Since `ListenAndServe` calls `net.Listen("tcp", ":7687")` with an empty host, Go binds the wildcard socket on all interfaces. ## Suggested Fix 1. Add a `Host string` field to `bolt.Config` (default `"

Properties

ghsa_id
GHSA-2hp7-65r3-wv54
severity
critical
summary
NornicDB has Improper Network Binding in its Bolt Server, allowing unauthorized remote access
cvss_score
9.8
cve_id
GHSA-2hp7-65r3-wv54
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-04-22T22:03:43Z
source_url
https://github.com/advisories/GHSA-2hp7-65r3-wv54
ghsa_updated
2026-04-22T22:03:46Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/orneryd/nornicdb

AFFECTS (1)

[Software]go/github.com/orneryd/nornicdb

HAS_WEAKNESS (1)

[Weakness]Use of Default Credentials

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph