GHSA-v2jf-442r-6mjh

Suggest an improvement
Source
https://github.com/advisories/GHSA-v2jf-442r-6mjh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v2jf-442r-6mjh/GHSA-v2jf-442r-6mjh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v2jf-442r-6mjh
Aliases
Published
2026-06-26T21:01:09Z
Modified
2026-07-07T16:11:36Z
Severity
  • 2.7 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction
Details

internal/api/pop/nonce.go:25,40,86 + internal/api/server.go:38 — the signed-poll nonce cache is an in-process LRU sized at 65,536 entries. internal/api/updates.go:31 sets pollClockSkew = 5 * time.Minute as the replay window.

Affected

All released versions through v0.3.0 that have shipped the ADR 0004 signed-poll path. (If this is gated behind a feature flag, on a side branch, or not yet on a release tag, please flag — this advisory may not apply to the released artifact yet.)

Threat model

A captured signed-poll request can be replayed:

  1. After any process restart — the in-memory LRU is wiped, so the original nonce becomes "unseen" again. Replay succeeds if the original timestamp is still within the 5-minute skew.
  2. After forced eviction — an attacker with control of any single host can flood >65,536 nonces under their own host_id, driving the global LRU to evict the victim's recorded nonce. Replay then succeeds.

Impact is bounded: a replayed poll fetches the /api/v1/agent/updates body. That body can include a freshly-minted enrollment token if a rekey is pending (updates.go:249-260) — at which point the attacker holds a single-use token they can redeem under their own keypair.

Suggested fix

Two options, either acceptable:

  1. Persist nonces in SQLite keyed by (host_id, nonce) with ON CONFLICT DO NOTHING, retained for the timestamp-skew window. Adds one transactional INSERT per poll; bounded by the skew window (~5 min worth of rows server-wide).
  2. Per-host cap on the LRU instead of a global 65k cap, so one host cannot evict another's records. Combined with shorter skew (≤30s) to bound the post-restart replay window.

Option 1 is more robust; option 2 is lower-implementation-effort.

Database specific
{
    "cwe_ids":  [
        "CWE-294"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-26T21:01:09Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

Go / github.com/juev/nebula-mesh

Package

Name
github.com/juev/nebula-mesh
View open source insights on deps.dev
Purl
pkg:golang/github.com/juev/nebula-mesh

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.3.4

Database specific

last_known_affected_version_range
"<= 0.3.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v2jf-442r-6mjh/GHSA-v2jf-442r-6mjh.json"