Security: forgekeep/nebula-mesh
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
nebula-mesh: CA signing keys not zeroized in ops restore verification loopGHSA-x9ww-x359-h3hq published
Sep 29, 2026 by juevModerate -
nebula-mesh: CA signing key not zeroized in credentialCutoverMasterGuard migrationGHSA-55pc-4j8c-8w76 published
Sep 29, 2026 by juevModerate -
TOTP shared secrets stored in cleartext in the operator databaseGHSA-pcj3-cv9c-q93x published
Sep 29, 2026 by juevModerate -
nebula-mesh agent rejects multi-cert CA bundle during rotation, blocking blocklist config deliveryGHSA-cqh8-3vvw-fwr9 published
Sep 29, 2026 by juevHigh -
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`GHSA-7rx3-5wx3-5v76 published
Jul 1, 2026 by juevHigh -
Certificate revocation is never enforced at the mesh: nebula-agent drops the polled blocklist and the generated config.yml has no pki.blocklist, so blocked/compromised hosts keep full mesh access until their cert expires (up to 30d agent / 365d mobile)GHSA-cm26-5974-52h8 published
Jun 23, 2026 by juevHigh -
Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokensGHSA-g4x6-jcvr-9m3g published
Jun 13, 2026 by juevModerate -
Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limitingGHSA-m3cx-mwpg-32jg published
Jun 13, 2026 by juevModerate -
Operator session tokens stored in plaintext in the databaseGHSA-q4vm-pq3q-8wgq published
Jun 4, 2026 by juevHigh -
CA private key not zeroized on web mobile-bundle error pathsGHSA-2p2f-px33-4vv5 published
Jun 4, 2026 by juevHigh