Wazuh server vulnerable to remote code execution
Affected range
SEMVER: introduced 4.4.0; fixed 4.9.1SEMVER: introduced 4.4.0+incompatible; fixed 4.9.1+incompatibleFixed versions: 4.9.1, 4.9.1+incompatible
Go package metadata, published advisories, affected versions, and known-exploitation evidence.
Evidence path
RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.
Latest version
v4.14.7+incompatible
No matching published advisory returned
Known exploitation
No KEV match
Checked by exact CVE identifier
Highest advisory severity
Critical
3 active advisories
The registry confirms the version, then OSV checks advisories for that exact value.
Published records
Affected range
SEMVER: introduced 4.4.0; fixed 4.9.1SEMVER: introduced 4.4.0+incompatible; fixed 4.9.1+incompatibleFixed versions: 4.9.1, 4.9.1+incompatible
Affected range
SEMVER: introduced 0; fixed 4.9.1+incompatibleFixed versions: 4.9.1+incompatible
Affected range
SEMVER: introduced 3.0.0+incompatible; fixed 4.9.0+incompatibleFixed versions: 4.9.0+incompatible