github.com/juev/nebula-mesh
Self-hosted control plane for Slack Nebula mesh VPN — issue certificates, manage hosts, distribute config from one place. Go + SQLite + htmx.
Activity
- Latest release
- 4h ago
- Total releases
- 38
- Cadence
- ~2 days
- Last 12 months
- 38
Reach
- Stars
- 25
Details
- First release
- May 11, 2026
| Version | Released | |
|---|---|---|
v0.16.3
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.3
patch
Dependencies (17)
+ 9 more |
|
v0.16.2
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.2
patch
Dependencies (17)
+ 9 more |
|
v0.16.1
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.1
patch
Dependencies (17)
+ 9 more |
|
v0.16.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (17)
+ 9 more |
|
v0.15.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.15.0
minor
Dependencies (17)
+ 9 more |
|
v0.14.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.14.0
minor
Dependencies (17)
+ 9 more |
|
v0.13.1
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.13.1
patch
Dependencies (18)
+ 10 more |
|
v0.13.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.13.0
minor
Dependencies (18)
+ 10 more |
|
v0.12.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.12.0
minor
Dependencies (18)
+ 10 more |
|
v0.11.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.11.0
minor
Dependencies (18)
+ 10 more |
|
v0.10.2
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.10.2
patch
Dependencies (18)
+ 10 more |
|
v0.10.1
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.10.1
patch
Dependencies (18)
+ 10 more |
|
v0.10.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.10.0
minor
Dependencies (19)
+ 11 more |
|
v0.9.1
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.9.1
patch
Dependencies (19)
+ 11 more |
|
v0.9.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.9.0
minor
Dependencies (19)
+ 11 more |
|
v0.8.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.8.0
minor
Dependencies (16)
+ 8 more |
|
v0.7.5
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.7.5
patch
Dependencies (16)
+ 8 more |
|
v0.7.4
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.7.4
patch
Dependencies (16)
+ 8 more |
|
v0.7.3
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.7.3
patch
Dependencies (16)
+ 8 more |
|
v0.7.2
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.7.2
patch
Dependencies (16)
+ 8 more |
|
v0.7.1
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.7.1
patch
Dependencies (16)
+ 8 more |
|
v0.7.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.7.0
minor
Dependencies (16)
+ 8 more |
|
v0.6.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (16)
+ 8 more |
|
v0.5.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (15)
+ 7 more |
|
v0.4.0
minor
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (14)
+ 6 more |
|
v0.3.8
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.3.8
patch
Dependencies (14)
+ 6 more |
|
v0.3.7
patch
3 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev |
v0.3.7
patch
Dependencies (14)
+ 6 more |
|
v0.3.6
patch
4 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.3.6
patch
Dependencies (14)
+ 6 more |
|
v0.3.5
patch
4 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.3.5
patch
Dependencies (14)
+ 6 more |
|
v0.3.4
patch
4 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.3.4
patch
Dependencies (14)
+ 6 more |
|
v0.3.3
patch
6 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
GO-2026-5815
GHSA-v2jf-442r-6mjh
Jul 07, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh Fixed in
0.3.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-47724
GO-2026-5139
GHSA-598g-h2vc-h5vg
Jun 25, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh Fixed in
0.3.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.3.3
patch
Dependencies (14)
+ 6 more |
|
v0.3.2
patch
7 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
GO-2026-5815
GHSA-v2jf-442r-6mjh
Jul 07, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh Fixed in
0.3.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-47724
GO-2026-5139
GHSA-598g-h2vc-h5vg
Jun 25, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh Fixed in
0.3.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47725
GO-2026-5049
GHSA-273q-qgh5-wrj6
Jun 16, 2026
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh Fixed in
0.3.3
Updated Jun 17, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.3.2
patch
Dependencies (14)
+ 6 more |
|
v0.3.1
patch
13 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
GO-2026-5815
GHSA-v2jf-442r-6mjh
Jul 07, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh Fixed in
0.3.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48058
GO-2026-5635
GHSA-rqfj-vv8r-xhqc
Jun 25, 2026
nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47726
GO-2026-5586
GHSA-qm33-p5p9-f8vg
Jun 25, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5399
GHSA-ghmh-jhmj-wcmf
Jun 25, 2026
nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47768
GO-2026-5294
GHSA-9pg3-25fq-p6cc
Jun 25, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5191
GHSA-6vgg-xhvh-38ff
Jun 25, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47722
GO-2026-5223
GHSA-7hp6-g3pq-3pc3
Jun 25, 2026
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47724
GO-2026-5139
GHSA-598g-h2vc-h5vg
Jun 25, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh Fixed in
0.3.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47725
GO-2026-5049
GHSA-273q-qgh5-wrj6
Jun 16, 2026
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh Fixed in
0.3.3
Updated Jun 17, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.3.1
patch
Dependencies (13)
+ 5 more |
|
v0.3.0
minor
14 CVEs
CVE-2026-55513
GO-2026-5987
GHSA-g4x6-jcvr-9m3g
Jul 23, 2026
Insecure enrollment token TTL in nebula-mesh in github.com/forgekeep/nebula-mesh The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token. References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
GO-2026-5815
GHSA-v2jf-442r-6mjh
Jul 07, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh Fixed in
0.3.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-47723
GO-2026-5698
GHSA-w7w5-5gcp-38rw
Jun 25, 2026
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh Fixed in
0.3.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48058
GO-2026-5635
GHSA-rqfj-vv8r-xhqc
Jun 25, 2026
nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47726
GO-2026-5586
GHSA-qm33-p5p9-f8vg
Jun 25, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5399
GHSA-ghmh-jhmj-wcmf
Jun 25, 2026
nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47768
GO-2026-5294
GHSA-9pg3-25fq-p6cc
Jun 25, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5191
GHSA-6vgg-xhvh-38ff
Jun 25, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47722
GO-2026-5223
GHSA-7hp6-g3pq-3pc3
Jun 25, 2026
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47724
GO-2026-5139
GHSA-598g-h2vc-h5vg
Jun 25, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh Fixed in
0.3.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47725
GO-2026-5049
GHSA-273q-qgh5-wrj6
Jun 16, 2026
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh Fixed in
0.3.3
Updated Jun 17, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (13)
+ 5 more |
|
v0.2.0
minor
13 CVEs
CVE-2026-55512
GO-2026-5989
GHSA-m3cx-mwpg-32jg
Jul 23, 2026
Unauthenticated OIDC login in nebula-mesh allows unbounded memory allocation in github.com/forgekeep/nebula-mesh When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map. An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service. References Updated Jul 23, 2026 · Source: OSV.dev
GO-2026-5815
GHSA-v2jf-442r-6mjh
Jul 07, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh Fixed in
0.3.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-47723
GO-2026-5698
GHSA-w7w5-5gcp-38rw
Jun 25, 2026
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh Fixed in
0.3.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48058
GO-2026-5635
GHSA-rqfj-vv8r-xhqc
Jun 25, 2026
nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47726
GO-2026-5586
GHSA-qm33-p5p9-f8vg
Jun 25, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5399
GHSA-ghmh-jhmj-wcmf
Jun 25, 2026
nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47768
GO-2026-5294
GHSA-9pg3-25fq-p6cc
Jun 25, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5191
GHSA-6vgg-xhvh-38ff
Jun 25, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47722
GO-2026-5223
GHSA-7hp6-g3pq-3pc3
Jun 25, 2026
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47724
GO-2026-5139
GHSA-598g-h2vc-h5vg
Jun 25, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh Fixed in
0.3.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47725
GO-2026-5049
GHSA-273q-qgh5-wrj6
Jun 16, 2026
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh Fixed in
0.3.3
Updated Jun 17, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (10)
+ 2 more |
|
v0.1.2
patch
12 CVEs
GO-2026-5815
GHSA-v2jf-442r-6mjh
Jul 07, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh Fixed in
0.3.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-47723
GO-2026-5698
GHSA-w7w5-5gcp-38rw
Jun 25, 2026
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh Fixed in
0.3.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48058
GO-2026-5635
GHSA-rqfj-vv8r-xhqc
Jun 25, 2026
nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47726
GO-2026-5586
GHSA-qm33-p5p9-f8vg
Jun 25, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5399
GHSA-ghmh-jhmj-wcmf
Jun 25, 2026
nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47768
GO-2026-5294
GHSA-9pg3-25fq-p6cc
Jun 25, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5191
GHSA-6vgg-xhvh-38ff
Jun 25, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47722
GO-2026-5223
GHSA-7hp6-g3pq-3pc3
Jun 25, 2026
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47724
GO-2026-5139
GHSA-598g-h2vc-h5vg
Jun 25, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh Fixed in
0.3.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47725
GO-2026-5049
GHSA-273q-qgh5-wrj6
Jun 16, 2026
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh Fixed in
0.3.3
Updated Jun 17, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.1.2
patch
Dependencies (7)
|
|
v0.1.1
patch
12 CVEs
GO-2026-5815
GHSA-v2jf-442r-6mjh
Jul 07, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh Fixed in
0.3.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-47723
GO-2026-5698
GHSA-w7w5-5gcp-38rw
Jun 25, 2026
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh Fixed in
0.3.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48058
GO-2026-5635
GHSA-rqfj-vv8r-xhqc
Jun 25, 2026
nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47726
GO-2026-5586
GHSA-qm33-p5p9-f8vg
Jun 25, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5399
GHSA-ghmh-jhmj-wcmf
Jun 25, 2026
nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47768
GO-2026-5294
GHSA-9pg3-25fq-p6cc
Jun 25, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5191
GHSA-6vgg-xhvh-38ff
Jun 25, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47722
GO-2026-5223
GHSA-7hp6-g3pq-3pc3
Jun 25, 2026
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47724
GO-2026-5139
GHSA-598g-h2vc-h5vg
Jun 25, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh Fixed in
0.3.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47725
GO-2026-5049
GHSA-273q-qgh5-wrj6
Jun 16, 2026
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh Fixed in
0.3.3
Updated Jun 17, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.1.1
patch
Dependencies (7)
|
|
v0.1.0
initial
12 CVEs
GO-2026-5815
GHSA-v2jf-442r-6mjh
Jul 07, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction in github.com/juev/nebula-mesh Fixed in
0.3.4
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49258
GO-2026-5816
GHSA-c6v2-3ffm-vcmc
Jul 07, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) in github.com/juev/nebula-mesh Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-47723
GO-2026-5698
GHSA-w7w5-5gcp-38rw
Jun 25, 2026
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) in github.com/juev/nebula-mesh Fixed in
0.3.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48058
GO-2026-5635
GHSA-rqfj-vv8r-xhqc
Jun 25, 2026
nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh nebula-mesh: Session and OIDC state cookies lack the Secure attribute in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47726
GO-2026-5586
GHSA-qm33-p5p9-f8vg
Jun 25, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5399
GHSA-ghmh-jhmj-wcmf
Jun 25, 2026
nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh nebula-mesh's stores enrollment tokens unhashed in SQLite in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47768
GO-2026-5294
GHSA-9pg3-25fq-p6cc
Jun 25, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) in github.com/juev/nebula-mesh Fixed in
0.3.2
Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5191
GHSA-6vgg-xhvh-38ff
Jun 25, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47722
GO-2026-5223
GHSA-7hp6-g3pq-3pc3
Jun 25, 2026
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml in github.com/juev/nebula-mesh Fixed in
0.3.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47724
GO-2026-5139
GHSA-598g-h2vc-h5vg
Jun 25, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation in github.com/juev/nebula-mesh Fixed in
0.3.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47725
GO-2026-5049
GHSA-273q-qgh5-wrj6
Jun 16, 2026
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints in github.com/juev/nebula-mesh Fixed in
0.3.3
Updated Jun 17, 2026 · Source: OSV.dev
CVE-2026-48025
GHSA-8h84-fhqq-q58v
GO-2026-5255
Jun 10, 2026
nebula-mesh: Decrypted CA private key persists in heap after signing
Medium
The keystore package's contract ( AffectedAll released versions up to v0.3.6. Threat modelMemory-read access: core dump, ptrace, kernel swap to disk, container/VM snapshot, OOM-debug bundle, side-channel via shared cache lines. Not a remote-network vulnerability, but defeats the master-key + envelope-encryption design's promise of "private key never lingers". Suggested fixAdd a
At each call site ( Optional follow-up: wrap Fixed in
0.3.7
References Updated Jun 26, 2026 · Source: OSV.dev |
v0.1.0
initial
Dependencies (7)
|