是一个自托管的 Slack Nebula mesh VPN 控制平面。在 0.3.7 版本之前,由于 在颁发证书时并未重新评估撤销/授权状态(仅在轮询时检查),导致本应不再被信任的主机仍能获取新的、有效的 Nebula 证书。具体存在两个相关的授权缺陷: 1. 封禁列表在签名/重新注册时未被强制生效 调用 时并未查询封禁列表;封禁列表仅在轮询路径中检查( 中的 )。由于封禁列表以证书指纹为键( ),重新注册会生成一个新的指纹,而该新指纹并不在封禁列表中,从而绕过封禁。 2. 证书续期时未重新校验操作者/CA 状态
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| forgekeep | nebula-mesh | < 0.3.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| forgekeep | nebula-mesh | < 0.3.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61699 | 8.1 HIGH | nebula-mesh: Certificate revocation is never enforced at the mesh |
| CVE-2026-63464 | 7.7 HIGH | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_priva |
| CVE-2026-53603 | 7.1 HIGH | nebula-mesh: Operator session tokens stored in plaintext in the database |
| CVE-2026-53604 | 7.1 HIGH | nebula-mesh: CA private key not zeroized on web mobile-bundle error paths |
| CVE-2026-55513 | 5.4 MEDIUM | nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hou |
| CVE-2026-55512 | 5.3 MEDIUM | nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entri |
No comments yet