Improper Security Headers in Nebula Mesh VPN Control Plane by Forgekeep
CVE-2026-47723

7.1HIGH

Key Information:

Vendor

Juev

Vendor
CVE Published:
23 July 2026

What is CVE-2026-47723?

Nebula Mesh, a self-hosted control plane for Slack Nebula mesh virtual private network, suffered from a security vulnerability due to the absence of crucial browser-security headers across its response paths before version 0.3.1. Headers such as Content-Security-Policy, X-Frame-Options, Strict-Transport-Security, X-Content-Type-Options, and Referrer-Policy were not set, potentially exposing users to various web-based attacks. The issue was addressed in version 0.3.1, which implemented the necessary headers to enhance overall security.

Affected Version(s)

nebula-mesh < 0.3.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.