---
id: CVE-2026-53602
title: nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
summary: >-
  nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to
  version 0.3.7, two related authorization gaps let a host that should no longer
  be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does
  n…
severity: medium
cwe:
  - CWE-285
  - CWE-862
  - CWE-613
vendor: forgekeep
product: github.com/forgekeep/nebula-mesh
affected:
  - github.com/forgekeep/nebula-mesh < 0.3.7
patched:
  - github.com/forgekeep/nebula-mesh 0.3.7
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T21:05:26.920'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53602'
references:
  - url: 'https://github.com/forgekeep/nebula-mesh/issues/178'
    label: security-advisories@github.com
  - url: 'https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.7'
    label: security-advisories@github.com
  - url: >-
      https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-339v-266x-79xr
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-339v-266x-79xr'
tags:
  - nvd
  - ghsa
  - go
epss: 0.00225
epssPercentile: 0.13457
aliases:
  - GHSA-339v-266x-79xr
ecosystem: go
ingestedAt: '2026-07-09T21:52:34.835Z'
---

## Overview

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate issuance time — only at poll time. Firstly, the blocklist is not enforced at sign / re-enroll time. internal/api/enroll.go:128 calls caMgr.Sign(...) without consulting the blocklist. The blocklist is only checked in the poll path (internal/api/updates.go:57, fingerprintInBlocklist). The blocklist is keyed by certificate fingerprint (internal/store/sqlite.go), so a re-enrollment produces a new fingerprint that is not in the blocklist. Secondly, renewal does not re-validate operator / CA status. Auto-renewal at poll time (internal/api/updates.go:285-319, signHostCert) reads host.Name, host.Groups, host.NebulaIPs from the DB and re-signs without checking whether the owning operator is still active or the CA still valid. DisableOperator (internal/store/sqlite_operators.go) revokes sessions and API keys but does not retire the operator's CAs, and pki/signer.go checks only CA cert time-expiry, not operator/CA status. This issue has been patched in version 0.3.7.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-53602)

Affected packages:

- `github.com/forgekeep/nebula-mesh < 0.3.7`

Patched in:

- `github.com/forgekeep/nebula-mesh 0.3.7`

Source: https://github.com/advisories/GHSA-339v-266x-79xr
