nebula-mesh 是一个自托管的 Slack Nebula 网状 VPN 控制平面。在 0.3.8 版本之前,Web 处理程序 将真实的 直接传递给 。在 函数内部, 会将 CA 的 Ed25519 私钥解密并生成 ,但 在任何返回路径上都没有调用 。因此,当通过 Web UI 发起移动捆绑包(mobile-bundle)请求并返回时——尤其是在发生错误(如缺少网络、无效的网段前缀、数据库错误或签名失败)时——明文的 CA 私钥会残留在 Go 堆内存中,直到被垃圾回收器清理。能够读取进程内存的攻击者(通过核心
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| forgekeep | nebula-mesh | < 0.3.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| forgekeep | nebula-mesh | < 0.3.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61699 | 8.1 HIGH | nebula-mesh: Certificate revocation is never enforced at the mesh |
| CVE-2026-63464 | 7.7 HIGH | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_priva |
| CVE-2026-53603 | 7.1 HIGH | nebula-mesh: Operator session tokens stored in plaintext in the database |
| CVE-2026-53602 | 6.9 MEDIUM | nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid |
| CVE-2026-55513 | 5.4 MEDIUM | nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hou |
| CVE-2026-55512 | 5.3 MEDIUM | nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entri |
No comments yet