Impact
The vulnerability is that Nebula‑Mesh never enforces certificate revocation. Although a host can be marked as blocked, the blocklist is never propagated to peers. A compromised host that has already been revoked still retains overlay reachability for up to 30 days on agent nodes or 365 days on mobile nodes, allowing the attacker to maintain connectivity to internal services while the operator believes the host is isolated.
Affected Systems
Forgekeep Nebula‑Mesh version 0.7.1 and earlier are affected. The issue was fixed in release v0.7.1 and the corresponding commit 0426e2f224a9b1e2029029bf923c93ed39d21cdb. Operators should ensure they are running 0.7.1 or later.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, but the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Attackers need to obtain a host’s key and certificate, which can be achieved through device compromise or credential theft. With those credentials they can run the nebula agent or the stock slackhq/nebula binary, ignore the agent’s 403/410 polling responses, and stay connected to the mesh for the full revocation window, potentially facilitating lateral movement and continued access to internal services.
OpenCVE Enrichment
Github GHSA