nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-subscriptions). No admin check exists on this field. At delivery time, allow_private switches the dispatcher to an unguarded HTTP client, bypassing the private/loopback/link-local SSRF guard — letting a low-privilege operator make the server request internal addresses. This issue has been patched in version 0.7.2.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Forgekeep
Forgekeep nebula-mesh |
|
| Vendors & Products |
Forgekeep
Forgekeep nebula-mesh |
Fri, 04 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-subscriptions). No admin check exists on this field. At delivery time, allow_private switches the dispatcher to an unguarded HTTP client, bypassing the private/loopback/link-local SSRF guard — letting a low-privilege operator make the server request internal addresses. This issue has been patched in version 0.7.2. | |
| Title | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` | |
| Weaknesses | CWE-862 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-09-04T19:44:10.117Z
Updated: 2026-09-08T17:50:11.907Z
Reserved: 2026-07-16T21:37:45.768Z
Link: CVE-2026-63464
Updated: 2026-09-08T17:50:07.779Z
Status : Deferred
Published: 2026-09-04T20:17:24.730
Modified: 2026-09-08T21:05:26.920
Link: CVE-2026-63464
No data.