Plaintext Key Exposure in nebula-mesh Control Plane
CVE-2026-48025

6.9MEDIUM

Key Information:

Vendor

Juev

Vendor
CVE Published:
28 July 2026

What is CVE-2026-48025?

The nebula-mesh control plane prior to version 0.3.7 suffered from a vulnerability where decrypted CA private keys could remain in memory unencrypted, allowing unauthorized access to sensitive information. This occurred due to the CAManager's failure to securely zero out plaintext data after use, resulting in potentially prolonged exposure in the process heap until garbage collection was performed. Affected components within the system did not adhere to proper key management protocols, thereby compromising the integrity of secure communications within the Slack Nebula mesh virtual private network. This issue was addressed with the patch implemented in version 0.3.7.

Affected Version(s)

nebula-mesh < 0.3.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.