๐Ÿ” CVE Alert

CVE-2026-47768

MEDIUM 5.5

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2.

CWE CWE-598
Vendor juev
Product nebula-mesh
Published Jul 28, 2026
Last Updated Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for juev nebula-mesh

Be the first to know when new medium vulnerabilities affecting juev nebula-mesh are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

juev / nebula-mesh
< 0.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-9pg3-25fq-p6cc github.com: https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.2