forgekeep nebula-mesh
7 known vulnerabilities in forgekeep nebula-mesh, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-63464 CVSS 7.7 high nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators…
- CVE-2026-61699 CVSS 8.1 high nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism…
- CVE-2026-55513 CVSS 5.4 medium nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI…
- CVE-2026-55512 CVSS 5.3 medium nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled…
- CVE-2026-53604 CVSS 7.1 high nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes…
- CVE-2026-53603 CVSS 7.1 high nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in…
- CVE-2026-53602 CVSS 6.9 medium nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host…