nebula-mesh 是一个自托管的 Slack Nebula mesh VPN 控制平面。在 0.3.8 版本之前,操作员会话令牌以明文形式存储在 表中( 列为主键)。会话令牌是一个 32 字节的随机十六进制值,直接通过 Cookie 发送,有效期为 24 小时。任何能够读取数据库的人(通过备份、快照、文件复制或 SQL 级别的信息泄露)都能获取所有活动的会话令牌,并直接劫持操作员会话,无需进一步的身份验证。该问题已在 0.3.8 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| forgekeep | nebula-mesh | < 0.3.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| forgekeep | nebula-mesh | < 0.3.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61699 | 8.1 HIGH | nebula-mesh: Certificate revocation is never enforced at the mesh |
| CVE-2026-63464 | 7.7 HIGH | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_priva |
| CVE-2026-53604 | 7.1 HIGH | nebula-mesh: CA private key not zeroized on web mobile-bundle error paths |
| CVE-2026-53602 | 6.9 MEDIUM | nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid |
| CVE-2026-55513 | 5.4 MEDIUM | nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hou |
| CVE-2026-55512 | 5.3 MEDIUM | nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entri |
No comments yet