github.com/juev/nebula-mesh vulnerabilities
CVEs whose affected-version data names the github.com/juev/nebula-mesh package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
12 CVEsRSS
GHSA-v2jf-442r-6mjhLownebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction
CVE-2026-49258High· 8.8Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
GHSA-ghmh-jhmj-wcmfMediumnebula-mesh's stores enrollment tokens unhashed in SQLite
nebula-mesh's stores enrollment tokens unhashed in SQLite
GHSA-6vgg-xhvh-38ffLownebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
CVE-2026-48025Mediumnebula-mesh: Decrypted CA private key persists in heap after signing
nebula-mesh: Decrypted CA private key persists in heap after signing
CVE-2026-48058Mediumnebula-mesh: Session and OIDC state cookies lack the Secure attribute
nebula-mesh: Session and OIDC state cookies lack the Secure attribute
CVE-2026-47768Medium· 5.5nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
CVE-2026-47722Highnebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
CVE-2026-47723Highnebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
CVE-2026-47724Critical· 9.9nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
CVE-2026-47725Highnebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
CVE-2026-47726Highnebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator