Memory Exposure in Nebula Mesh VPN Affecting Forgekeep
CVE-2026-53604

7.1HIGH

Key Information:

Vendor

Forgekeep

Vendor
CVE Published:
4 September 2026

What is CVE-2026-53604?

A memory exposure vulnerability in Nebula Mesh VPN prior to version 0.3.8 allows the CA's ed25519 private key to remain in plaintext on the Go heap after certain web handler processes. Specifically, when the renderMobileBundle function executes, it fails to properly wipe sensitive cryptographic data from memory upon various error conditions. This flaw permits an attacker with memory access to read and extract the CA signing key, possibly enabling them to mint unauthorized host certificates for the mesh network. The vulnerability has been addressed in version 0.3.8.

Affected Version(s)

nebula-mesh < 0.3.8

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.