Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-63464
  • github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` 04 Sep
  • Fix available
  • Severity - 7.7 (High)
CVE-2026-61699
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Certificate revocation is never enforced at the mesh 04 Sep
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-55513
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens 04 Sep
  • Fix available
  • Severity - 5.4 (Medium)
CVE-2026-55512
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting 04 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-53604
  • github.com/forgekeep/nebula-mesh
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths 04 Sep
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-53603
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Operator session tokens stored in plaintext in the database 04 Sep
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-53602
  • github.com/forgekeep/nebula-mesh
nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid certificate 04 Sep
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2026-49258
  • github.com/forgekeep/nebula-mesh
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) 28 Jul
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-48058
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Session and OIDC state cookies lack the Secure attribute 28 Jul
  • Fix available
  • Severity - 4.6 (Medium)
CVE-2026-47768
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) 28 Jul
  • Fix available
  • Severity - 5.5 (Medium)
CVE-2026-47726
  • github.com/forgekeep/nebula-mesh
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator 28 Jul
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-47725
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Web UI lacks CSRF tokens on /ui/* mutating endpoints 28 Jul
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2026-48025
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Decrypted CA private key persists in heap after signing 28 Jul
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2026-47724
  • github.com/forgekeep/nebula-mesh
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation 23 Jul
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2026-47723
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) 23 Jul
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-47722
  • github.com/forgekeep/nebula-mesh
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml 23 Jul
  • Fix available
  • Severity - 8.7 (High)