Plaintext Key Exposure in nebula-mesh Control Plane
CVE-2026-48025
6.9MEDIUM
What is CVE-2026-48025?
The nebula-mesh control plane prior to version 0.3.7 suffered from a vulnerability where decrypted CA private keys could remain in memory unencrypted, allowing unauthorized access to sensitive information. This occurred due to the CAManager's failure to securely zero out plaintext data after use, resulting in potentially prolonged exposure in the process heap until garbage collection was performed. Affected components within the system did not adhere to proper key management protocols, thereby compromising the integrity of secure communications within the Slack Nebula mesh virtual private network. This issue was addressed with the patch implemented in version 0.3.7.
Affected Version(s)
nebula-mesh < 0.3.7
