github.com/forgekeep/nebula-mesh
Go7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/forgekeep/nebula-meshpage 1 of 1
- CVE-2026-48025MEDIUMEG 0.0✓ Fixed in 0.3.72026-06-10
nebula-mesh: Decrypted CA private key persists in heap after signing `internal/pki/resolver.go:36-64` constructs a `CAManager` with the plaintext `ed25519.PrivateKey` after unwrapping via the master key; `internal/pki/ca.go:13-16` stores …
- CVE-2026-53602MEDIUMEG 0.0✓ Fixed in 0.3.72026-07-09
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate ## Summary Two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because…
- CVE-2026-53603HIGHEG 0.0✓ Fixed in 0.3.82026-07-14
nebula-mesh: Operator session tokens stored in plaintext in the database ## Impact Operator session tokens are stored in plaintext in the `operator_sessions` table (the `token` column is the PRIMARY KEY). The session token is a 32-byte r…
- CVE-2026-53604HIGHEG 0.0✓ Fixed in 0.3.82026-07-14
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths ## Impact The web handler `renderMobileBundle` (`internal/web/handlers.go:1325`) passes the real `*pki.CAResolver` directly into `mobilebundle.Build`. Inside `Buil…
- CVE-2026-55512MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.5.02026-07-14
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting ### Summary When OIDC is enabled, `GET /ui/oidc/login` is reachable without authentication and is registered outside the We…
- CVE-2026-55513MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.5.02026-07-14
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens ### Summary The `nebula-mgmt` Web UI host-creation path ignores both the server-wide `enrollment_token_ttl` security sett…
- CVE-2026-61699HIGHCVSS 8.1EG 8.1✓ Fixed in 0.7.12026-07-14
nebula-mesh: Certificate revocation is never enforced at the mesh ### Summary nebula-mesh revokes a host by adding its certificate fingerprint to a per-CA blocklist and shipping that list to every other agent on each poll. Slack's Nebula…
Check whether github.com/forgekeep/nebula-mesh is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/forgekeep/nebula-mesh CVEs against the assets you own.
Start Free Scan →