Memory Exposure in Nebula Mesh VPN Affecting Forgekeep
CVE-2026-53604
7.1HIGH
What is CVE-2026-53604?
A memory exposure vulnerability in Nebula Mesh VPN prior to version 0.3.8 allows the CA's ed25519 private key to remain in plaintext on the Go heap after certain web handler processes. Specifically, when the renderMobileBundle function executes, it fails to properly wipe sensitive cryptographic data from memory upon various error conditions. This flaw permits an attacker with memory access to read and extract the CA signing key, possibly enabling them to mint unauthorized host certificates for the mesh network. The vulnerability has been addressed in version 0.3.8.
Affected Version(s)
nebula-mesh < 0.3.8
