VulnSea

forgekeep has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 7.1 (high). None have a confirmed exploitation report. The most common weakness class is CWE-862 (3). Most affected products: nebula-mesh (6), github.com/forgekeep/nebula-mesh (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
9 prev 0

Products

  • nebula-mesh 6
  • github.com/forgekeep/nebula-mesh 3
9
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

forgekeep vulnerabilities

CVEs affecting forgekeep, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-63464High· 7.7PoC
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/w…

Midnightforgekeep · nebula-meshEPSS 0.27%via NVD
CVE-2026-53604High· 7.1
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.LoadByID decrypts t…

Twilightforgekeep · nebula-meshEPSS 0.12%via NVD
CVE-2026-53603High· 7.1
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32…

Twilightforgekeep · nebula-meshEPSS 0.20%via NVD
CVE-2026-55512Medium· 5.3PoC
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limi…

Twilightforgekeep · nebula-meshEPSS 0.33%via NVD
CVE-2026-55513Medium· 5.4PoC
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-networ…

Twilightforgekeep · nebula-meshEPSS 0.19%via NVD
CVE-2026-61699High· 8.1PoC
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches an…

Midnightforgekeep · nebula-meshEPSS 0.25%via NVD
CVE-2026-53602Medium
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does n…

Sunlitforgekeep · github.com/forgekeep/nebula-meshEPSS 0.22%via NVD
GO-2026-5985None
2mo ago

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh

Sunlitforgekeep · github.com/forgekeep/nebula-meshvia OSV
GHSA-7rx3-5wx3-5v76High· 7.7
2mo ago

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Twilightforgekeep · github.com/forgekeep/nebula-meshvia GHSA
forgekeep vulnerabilities (CVEs) · VulnSea