API Key Exposure in Nebula Mesh by Forgekeep
CVE-2026-47768

5.5MEDIUM

Key Information:

Vendor

Juev

Vendor
CVE Published:
28 July 2026

What is CVE-2026-47768?

Nebula Mesh, a self-hosted control plane for managing a Slack Nebula mesh virtual private network, contains a vulnerability that could expose newly minted operator API keys in redirect URLs, including Referer and history logs. This issue poses a security risk as sensitive information may be inadvertently leaked through proxy logs. The vulnerability has been resolved in version 0.3.2, and users are urged to upgrade to this version to ensure their systems remain secure.

Affected Version(s)

nebula-mesh < 0.3.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.