Vulnerability in Nebula-Mesh Control Plane for Slack - Bypass of SSRF Guard
CVE-2026-63464
7.7HIGH
What is CVE-2026-63464?
A vulnerability in the Nebula-Mesh control plane, particularly affecting versions 0.6.0 through 0.7.0, allows non-admin operators to manipulate their webhook subscriptions. By setting the 'allow_private' flag to true without any administrative validation, these operators can make unauthorized server requests to internal network addresses. This breaks established security measures designed to prevent SSRF attacks, putting sensitive internal systems at risk. The issue was addressed in version 0.7.2.
Affected Version(s)
nebula-mesh >= 0.6.0, < 0.7.2
