CVE-2026-47768: Juev Nebula-Mesh
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2.
Affected products
- Juev Nebula-Mesh: before 0.3.2 (fixed in 0.3.2)
Published 2026-07-28. Last modified 2026-07-30.