nebula-mesh 是一个自托管的 Slack Nebula 网格 VPN 控制平面。在 0.7.1 版本之前,吊销(revocation)是隔离已失陷或已离场主机的唯一带内机制。由于黑名单(blocklist)从未同步到任何对等节点的 config.yml 文件中,被标记为“已阻塞”的主机在最多 30 天(代理)/ 365 天(移动端)内,仍能通过其证书颁发机构(CA)下的每个对等节点及网格内的内部服务保持完全的覆盖网络可达性。攻击者若泄露了 host.key 和 host.crt,可以直接运行原版 slac
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| forgekeep | nebula-mesh | < 0.7.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| forgekeep | nebula-mesh | < 0.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63464 | 7.7 HIGH | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_priva |
| CVE-2026-53603 | 7.1 HIGH | nebula-mesh: Operator session tokens stored in plaintext in the database |
| CVE-2026-53604 | 7.1 HIGH | nebula-mesh: CA private key not zeroized on web mobile-bundle error paths |
| CVE-2026-53602 | 6.9 MEDIUM | nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid |
| CVE-2026-55513 | 5.4 MEDIUM | nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hou |
| CVE-2026-55512 | 5.3 MEDIUM | nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entri |
No comments yet