github.com/juev/nebula-mesh
Go11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/juev/nebula-meshpage 1 of 1
- CVE-2026-47722HIGHCVSS 8.7EG 8.7✓ Fixed in 0.3.22026-06-08
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into …
- CVE-2026-47723HIGHCVSS 7.1EG 7.1✓ Fixed in 0.3.12026-06-08
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Conte…
- CVE-2026-47724CRITICALCVSS 9.9EG 9.9✓ Fixed in 0.3.42026-06-08
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits t…
- CVE-2026-47725MEDIUMCVSS 6.9EG 6.9✓ Fixed in 0.3.32026-06-08
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DELETE route processes the request as soon as the session cookie validates. SameSite=Lax on …
- CVE-2026-47726HIGHCVSS 7.1EG 7.1✓ Fixed in 0.3.22026-06-08
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check. The route is bearer-auth gated only; any operator API key…
- CVE-2026-47768MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.3.22026-06-10
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version …
- CVE-2026-48025MEDIUMCVSS 6.9EG 6.9✓ Fixed in 0.3.72026-06-10
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey after unwrapping via the master k…
- CVE-2026-48058MEDIUMCVSS 4.6EG 4.6✓ Fixed in 0.3.22026-06-10
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single pla…
- CVE-2026-49258HIGHCVSS 8.8EG 8.82026-06-26
Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h…
- CVE-2026-55512MEDIUMCVSS 5.3EG 5.32026-07-14
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting ### Summary When OIDC is enabled, `GET /ui/oidc/login` is reachable without authentication and is registered outside the We…
- CVE-2026-55513MEDIUMCVSS 5.4EG 5.42026-07-14
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens ### Summary The `nebula-mgmt` Web UI host-creation path ignores both the server-wide `enrollment_token_ttl` security sett…
Check whether github.com/juev/nebula-mesh is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/juev/nebula-mesh CVEs against the assets you own.
Start Free Scan →