Forgekeep nebula-mesh是Forgekeep团队的一系列网络代理和VPN整合软件。 Forgekeep nebula-mesh 0.3.3之前版本存在跨站请求伪造漏洞,该漏洞源于会话cookie验证后立即处理请求,导致容易受到跨站请求伪造攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| juev | nebula-mesh | < 0.3.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| juev | nebula-mesh | < 0.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49258 | 8.8 HIGH | Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and ne |
| CVE-2026-47726 | 7.1 HIGH | nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator |
| CVE-2026-48025 | 6.9 MEDIUM | nebula-mesh: Decrypted CA private key persists in heap after signing |
| CVE-2026-47768 | 5.5 MEDIUM | nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, prox |
| CVE-2026-48058 | 4.6 MEDIUM | nebula-mesh: Session and OIDC state cookies lack the Secure attribute |
No comments yet