Impact
A host that has been blocked or offboarded can obtain a new, valid Nebula VPN certificate because the control plane does not re-evaluate revocation at the time of issuance. The vulnerability allows an unauthorized or compromised host to be re-enrolled and therefore re-established on the mesh, potentially compromising confidentiality, integrity, and availability of the network. The weakness is an authorization failure that permits certificate issuance and renewal without checking the host’s current block status or operator/CA validity, exposing the system to misuse of privileged credentials.
Affected Systems
forgekeep:nebula-mesh – the nebula-mesh control plane. All releases prior to version 0.3.7 are affected; the patch is supplied in release v0.3.7. No other versions or vendors are indicated.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires that an attacker has some ability to interact with the nebula-mgmt API or to host a re-enrollment request, which is usually restricted to internal network traffic. Because the blocklist is only enforced at poll time, a revoked host can bypass revocation immediately upon re-enrollment, making the attack practical if the attacker gains sufficient API access.
OpenCVE Enrichment
Github GHSA