Description
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9pg3-25fq-p6cc | nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) |
References
History
Tue, 28 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2. | |
| Title | nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-28T18:47:53.458Z
Reserved: 2026-05-19T22:36:16.882Z
Link: CVE-2026-47768
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-598
Use of HTTP Request With Sensitive Query String
Github GHSA