Improper Security Headers in Nebula Mesh VPN Control Plane by Forgekeep
CVE-2026-47723
7.1HIGH
What is CVE-2026-47723?
Nebula Mesh, a self-hosted control plane for Slack Nebula mesh virtual private network, suffered from a security vulnerability due to the absence of crucial browser-security headers across its response paths before version 0.3.1. Headers such as Content-Security-Policy, X-Frame-Options, Strict-Transport-Security, X-Content-Type-Options, and Referrer-Policy were not set, potentially exposing users to various web-based attacks. The issue was addressed in version 0.3.1, which implemented the necessary headers to enhance overall security.
Affected Version(s)
nebula-mesh < 0.3.1
