github.com/forgekeep/nebula-mesh
Go8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/forgekeep/nebula-meshpage 1 of 1
- CVE-2026-48025MEDIUMCVSS 6.9EG 6.9✓ Fixed in 0.3.72026-06-10
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey after unwrapping via the master k…
- CVE-2026-53602MEDIUMCVSS 6.9EG 6.9✓ Fixed in 0.3.72026-07-09
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not…
- CVE-2026-53603HIGHCVSS 7.1EG 7.1✓ Fixed in 0.3.82026-07-14
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-b…
- CVE-2026-53604HIGHCVSS 7.1EG 7.1✓ Fixed in 0.3.82026-07-14
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.LoadByID decrypts the…
- CVE-2026-55512MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.5.02026-07-14
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limite…
- CVE-2026-55513MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.5.02026-07-14
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-network …
- CVE-2026-61699HIGHCVSS 8.1EG 8.1✓ Fixed in 0.7.12026-07-14
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any …
- CVE-2026-63464HIGHCVSS 7.7EG 7.7✓ Fixed in 0.7.22026-09-04
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/web…
Check whether github.com/forgekeep/nebula-mesh is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/forgekeep/nebula-mesh CVEs against the assets you own.
Start Free Scan →