github.com/forgekeep/nebula-mesh
Self-hosted control plane for Slack Nebula mesh VPN — issue certificates, manage hosts, distribute config from one place. Go + SQLite + htmx.
Activity
- Latest release
- 5d ago
- Total releases
- 37
- Cadence
- ~2 days
- Last 12 months
- 37
Reach
- Stars
- 25
Details
- First release
- May 11, 2026
| Version | Released | |
|---|---|---|
v0.16.2
patch
|
v0.16.2
patch
Dependencies (17)
+ 9 more |
|
v0.16.1
patch
|
v0.16.1
patch
Dependencies (17)
+ 9 more |
|
v0.16.0
minor
|
v0.16.0
minor
Dependencies (17)
+ 9 more |
|
v0.15.0
minor
|
v0.15.0
minor
Dependencies (17)
+ 9 more |
|
v0.14.0
minor
|
v0.14.0
minor
Dependencies (17)
+ 9 more |
|
v0.13.1
patch
|
v0.13.1
patch
Dependencies (18)
+ 10 more |
|
v0.13.0
minor
|
v0.13.0
minor
Dependencies (18)
+ 10 more |
|
v0.12.0
minor
|
v0.12.0
minor
Dependencies (18)
+ 10 more |
|
v0.11.0
minor
|
v0.11.0
minor
Dependencies (18)
+ 10 more |
|
v0.10.2
patch
|
v0.10.2
patch
Dependencies (18)
+ 10 more |
|
v0.10.1
patch
|
v0.10.1
patch
Dependencies (18)
+ 10 more |
|
v0.10.0
minor
|
v0.10.0
minor
Dependencies (19)
+ 11 more |
|
v0.9.1
patch
|
v0.9.1
patch
Dependencies (19)
+ 11 more |
|
v0.9.0
minor
|
v0.9.0
minor
Dependencies (19)
+ 11 more |
|
v0.8.0
minor
|
v0.8.0
minor
Dependencies (16)
+ 8 more |
|
v0.7.5
patch
|
v0.7.5
patch
Dependencies (16)
+ 8 more |
|
v0.7.4
patch
|
v0.7.4
patch
Dependencies (16)
+ 8 more |
|
v0.7.3
patch
|
v0.7.3
patch
Dependencies (16)
+ 8 more |
|
v0.7.2
patch
|
v0.7.2
patch
Dependencies (16)
+ 8 more |
|
v0.7.1
patch
1 CVE
CVE-2026-63464
GO-2026-5985
GHSA-7rx3-5wx3-5v76
Jul 17, 2026
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh Nebula-mesh allows non-admin operators to disable webhook SSRF protection via Fixed in
0.7.2
References Updated Sep 05, 2026 · Source: OSV.dev |
v0.7.1
patch
Dependencies (16)
+ 8 more |
|
v0.7.0
minor
2 CVEs
CVE-2026-63464
GO-2026-5985
GHSA-7rx3-5wx3-5v76
Jul 17, 2026
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh Nebula-mesh allows non-admin operators to disable webhook SSRF protection via Fixed in
0.7.2
References Updated Sep 05, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev |
v0.7.0
minor
Dependencies (16)
+ 8 more |
|
v0.6.0
minor
2 CVEs
CVE-2026-63464
GO-2026-5985
GHSA-7rx3-5wx3-5v76
Jul 17, 2026
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh Nebula-mesh allows non-admin operators to disable webhook SSRF protection via Fixed in
0.7.2
References Updated Sep 05, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (16)
+ 8 more |
|
v0.5.0
minor
1 CVE
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (15)
+ 7 more |
|
v0.4.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. Fixed in
0.5.0
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. Fixed in
0.5.0
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (14)
+ 6 more |
|
v0.3.8
patch
1 CVE
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev |
v0.3.8
patch
Dependencies (14)
+ 6 more |
|
v0.3.7
patch
3 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev |
v0.3.7
patch
Dependencies (14)
+ 6 more |
|
v0.3.6
patch
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.3.6
patch
Dependencies (14)
+ 6 more |
|
v0.3.5
patch
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.3.5
patch
Dependencies (14)
+ 6 more |
|
v0.3.4
patch
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.3.4
patch
Dependencies (14)
+ 6 more |
|
v0.3.3
patch
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.3.3
patch
Dependencies (14)
+ 6 more |
|
v0.3.2
patch
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.3.2
patch
Dependencies (14)
+ 6 more |
|
v0.3.1
patch
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.3.1
patch
Dependencies (13)
+ 5 more |
|
v0.3.0
minor
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (13)
+ 5 more |
|
v0.2.0
minor
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (10)
+ 2 more |
|
v0.1.2
patch
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.1.2
patch
Dependencies (7)
|
|
v0.1.1
patch
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.1.1
patch
Dependencies (7)
|
|
v0.1.0
initial
5 CVEs
CVE-2026-53603
GO-2026-5991
GHSA-q4vm-pq3q-8wgq
Jul 17, 2026
nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53604
GO-2026-5984
GHSA-2p2f-px33-4vv5
Jul 17, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh Fixed in
0.3.8
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-53602
GO-2026-5950
GHSA-339v-266x-79xr
Jul 17, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-61699
GO-2026-5986
GHSA-cm26-5974-52h8
Jul 17, 2026
nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh Fixed in
0.7.1
References Updated Jul 21, 2026 · Source: OSV.dev
CVE-2026-48025
GO-2026-5255
GHSA-8h84-fhqq-q58v
Jun 25, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh nebula-mesh: Decrypted CA private key persists in heap after signing in github.com/forgekeep/nebula-mesh Fixed in
0.3.7
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.1.0
initial
Dependencies (7)
|