nebula-mesh 是一个自托管的 Slack Nebula 网状 VPN 控制平面。从版本 0.6.0 到 0.7.2 之前,非管理员操作员(角色为 user)可以在其管理的 Webhook 订阅中设置 (通过 )。该字段缺少管理员权限校验。在事件分发时,启用 会使调度器切换到一个无保护的 HTTP 客户端,从而绕过针对私有/回环/链路本地地址的 SSRF 防护机制——使得低权限操作员能够触发服务器向内网地址发起请求。该问题已在版本 0.7.2 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| forgekeep | nebula-mesh | >= 0.6.0, < 0.7.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| forgekeep | nebula-mesh | >= 0.6.0, < 0.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61699 | 8.1 HIGH | nebula-mesh: Certificate revocation is never enforced at the mesh |
| CVE-2026-53603 | 7.1 HIGH | nebula-mesh: Operator session tokens stored in plaintext in the database |
| CVE-2026-53604 | 7.1 HIGH | nebula-mesh: CA private key not zeroized on web mobile-bundle error paths |
| CVE-2026-53602 | 6.9 MEDIUM | nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid |
| CVE-2026-55513 | 5.4 MEDIUM | nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hou |
| CVE-2026-55512 | 5.3 MEDIUM | nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entri |
No comments yet