forgekeep has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 7.1 (high). None have a confirmed exploitation report. The most common weakness class is CWE-862 (3). Most affected products: nebula-mesh (6), github.com/forgekeep/nebula-mesh (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 9 prev 0
Products
- nebula-mesh 6
- github.com/forgekeep/nebula-mesh 3
Worst active — by depth score
CVE-2026-61699High· 8.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN57CVE-2026-63464High· 7.7nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN54CVE-2026-55513Medium· 5.4nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN42GHSA-7rx3-5wx3-5v76High· 7.7Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`42CVE-2026-55512Medium· 5.3nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN41
forgekeep vulnerabilities
CVEs affecting forgekeep, newest first. Open any entry for full detail, references, and exploit status.
9 CVEsRSS
CVE-2026-63464High· 7.7PoCnebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/w…
CVE-2026-53604High· 7.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.LoadByID decrypts t…
CVE-2026-53603High· 7.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32…
CVE-2026-55512Medium· 5.3PoCnebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limi…
CVE-2026-55513Medium· 5.4PoCnebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-networ…
CVE-2026-61699High· 8.1PoCnebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches an…
CVE-2026-53602Mediumnebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does n…
GO-2026-5985NoneNebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
GHSA-7rx3-5wx3-5v76High· 7.7Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`