CVE-2026-47723

Published: Lug 23, 2026 Last Modified: Lug 24, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,1
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Content-Security-Policy`, `X-Frame-Options`, `Strict-Transport-Security`, `X-Content-Type-Options`, `Referrer-Policy` returns zero matches across the codebase. Version 0.3.1 fixes the issue.

1021

Improper Restriction of Rendered UI Layers or Frames

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity Bypass Protection Mechanism Read Application Data Modify Application Data
Applicable Platforms
Technologies: Not Technology-Specific, Web Based
View CWE Details
https://github.com/forgekeep/nebula-mesh/commit/b45fda5476c41ffcff1ca23058aef0f…
https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.1
https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-w7w5-5gcp-38rw