VulnSea

github.com/juev/nebula-mesh vulnerabilities

CVEs whose affected-version data names the github.com/juev/nebula-mesh package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

GHSA-v2jf-442r-6mjhLow
2mo ago

nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction

nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction

Sunlitjuev · github.com/juev/nebula-meshvia GHSA
CVE-2026-49258High· 8.8
2mo ago

Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)

Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)

Twilightjuev · github.com/juev/nebula-meshEPSS 0.28%via GHSA
GHSA-ghmh-jhmj-wcmfMedium
3mo ago

nebula-mesh's stores enrollment tokens unhashed in SQLite

nebula-mesh's stores enrollment tokens unhashed in SQLite

Sunlitjuev · github.com/juev/nebula-meshvia GHSA
GHSA-6vgg-xhvh-38ffLow
3mo ago

nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store

nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store

Sunlitjuev · github.com/juev/nebula-meshvia GHSA
CVE-2026-48025Medium
3mo ago

nebula-mesh: Decrypted CA private key persists in heap after signing

nebula-mesh: Decrypted CA private key persists in heap after signing

Sunlitjuev · github.com/juev/nebula-meshEPSS 0.29%via GHSA
CVE-2026-48058Medium
3mo ago

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

Sunlitjuev · github.com/juev/nebula-meshEPSS 0.19%via GHSA
CVE-2026-47768Medium· 5.5
3mo ago

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

Sunlitjuev · github.com/juev/nebula-meshEPSS 0.11%via GHSA
CVE-2026-47722High
3mo ago

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

Twilightjuev · github.com/juev/nebula-meshEPSS 0.47%via GHSA
CVE-2026-47723High
3mo ago

nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)

nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)

Twilightjuev · github.com/juev/nebula-meshEPSS 0.53%via GHSA
CVE-2026-47724Critical· 9.9
3mo ago

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

Midnightjuev · github.com/juev/nebula-meshEPSS 0.48%via GHSA
CVE-2026-47725High
3mo ago

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

Twilightjuev · github.com/juev/nebula-meshEPSS 0.15%via GHSA
CVE-2026-47726High
3mo ago

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

Twilightjuev · github.com/juev/nebula-meshEPSS 0.24%via GHSA
github.com/juev/nebula-mesh vulnerabilities (CVEs) · VulnSea