CVE-2026-47723
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in internal/web/ or internal/api/ set the standard browser-security headers. grep for Content-Security-Policy, X-Frame-Options, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy returns zero matches across the codebase. Version 0.3.1 fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| juev | nebula-mesh | < 0.3.1 | affected |
Weaknesses
- CWE-1021: CWE-1021: Improper Restriction of Rendered UI Layers or Frames
References
- https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-w7w5-5gcp-38rw
- https://github.com/forgekeep/nebula-mesh/commit/b45fda5476c41ffcff1ca23058aef0fb851359c1
- https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.