CVE Browser
CVE-2026-63464 HIGH
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
CVSS 7.7 EPSS 0.46% Sep 4, 2026
Go
CVE-2026-61699 HIGH
nebula-mesh: Certificate revocation is never enforced at the mesh
CVSS 8.1 EPSS 0.45% Sep 4, 2026
Go
CVE-2026-55513 MEDIUM
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
CVSS 5.4 EPSS 0.32% Sep 4, 2026
Go
CVE-2026-55512 MEDIUM
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting
CVSS 5.3 EPSS 0.60% Sep 4, 2026
Go
CVE-2026-53604 HIGH
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
CVSS 8.7 EPSS 0.18% Sep 4, 2026
Go
CVE-2026-53603 HIGH
nebula-mesh: Operator session tokens stored in plaintext in the database
CVSS 7.1 EPSS 0.35% Sep 4, 2026
Go
CVE-2026-53602 MEDIUM
nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid certificate
CVSS 6.9 EPSS 0.31% Sep 4, 2026
Go
Showing 1 to 7 CVEs · page 1