nebula-mesh 是一个自托管的 Slack Nebula mesh VPN 控制平面组件。在 0.3.0 到 0.5.0 之前的版本中,nebula-mgmt 的 Web UI 主机创建流程忽略了全局安全设置中的 以及按网络配置的 覆盖值。虽然通过 API 创建主机和重新生成令牌的流程会正确使用已配置的 TTL 解析器,但 端点为新生成的代理入网令牌硬编码了 24 小时的有效性时长( )。因此,在那些有意缩短入网令牌有效期的部署环境中,任何能够登录 Web UI 创建主机的认证操作员,仍然可以签发一个有效期
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| forgekeep | nebula-mesh | >= 0.3.0, < 0.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| forgekeep | nebula-mesh | >= 0.3.0, < 0.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61699 | 8.1 HIGH | nebula-mesh: Certificate revocation is never enforced at the mesh |
| CVE-2026-63464 | 7.7 HIGH | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_priva |
| CVE-2026-53603 | 7.1 HIGH | nebula-mesh: Operator session tokens stored in plaintext in the database |
| CVE-2026-53604 | 7.1 HIGH | nebula-mesh: CA private key not zeroized on web mobile-bundle error paths |
| CVE-2026-53602 | 6.9 MEDIUM | nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid |
| CVE-2026-55512 | 5.3 MEDIUM | nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entri |
No comments yet