github.com/forgekeep/nebula-mesh vulnerabilities
CVEs whose affected-version data names the github.com/forgekeep/nebula-mesh package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-53602Mediumnebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does n…
GO-2026-5985NoneNebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
GHSA-7rx3-5wx3-5v76High· 7.7Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
CVE-2026-48025Mediumnebula-mesh: Decrypted CA private key persists in heap after signing
nebula-mesh: Decrypted CA private key persists in heap after signing