---
id: GO-2026-5985
aliases:
  - GHSA-7rx3-5wx3-5v76
title: >-
  Nebula-mesh allows non-admin operators to disable webhook SSRF protection via
  `allow_private` in github.com/forgekeep/nebula-mesh
summary: >-
  Nebula-mesh allows non-admin operators to disable webhook SSRF protection via
  `allow_private` in github.com/forgekeep/nebula-mesh
severity: none
vendor: forgekeep
product: github.com/forgekeep/nebula-mesh
ecosystem: go
affected:
  - 'github.com/forgekeep/nebula-mesh >= 0.6.0, < 0.7.2'
patched:
  - github.com/forgekeep/nebula-mesh 0.7.2
published: '2026-07-17'
updated: '2026-07-21'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-5985'
references:
  - url: >-
      https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7rx3-5wx3-5v76
  - url: >-
      https://github.com/forgekeep/nebula-mesh/commit/f3c54530e388dd21763e548923426e60a8e93ff0
  - url: 'https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.2'
tags:
  - osv
  - go
ingestedAt: '2026-07-22T15:33:23.806Z'
---

## Overview

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh

## Affected packages

- `github.com/forgekeep/nebula-mesh >= 0.6.0, < 0.7.2`

## Remediation

Upgrade to a patched release:

- `github.com/forgekeep/nebula-mesh 0.7.2`
