CVE-2026-48058
CVE-2026-48058 is a medium-severity vulnerability with a CVSS 4.0 base score of 4.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-614.
Key facts
- Severity: Medium (CVSS 4.0 base score 4.6)
- EPSS exploit prediction: 0% (9th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-614
- Published:
- Last modified:
Description
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session. This issue has been patched in version 0.3.2.
Frequently asked questions
- What is CVE-2026-48058?
- nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session. This issue has been patched in version 0.3.2.
- How severe is CVE-2026-48058?
- CVE-2026-48058 has a CVSS 4.0 base score of 4.6, rated medium severity.
- Is CVE-2026-48058 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (9th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-48058?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-48058 published?
- CVE-2026-48058 was published on 2026-07-28 and last updated on 2026-07-30.
References
- https://github.com/forgekeep/nebula-mesh/commit/ffdd67dbf221d9a5855c39fbe11b49c245048d85
- https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.2
- https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-rqfj-vv8r-xhqc
Other CWE-614 vulnerabilities
- CVE-2025-8037 — Critical (CVSS 9.1): Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set…
- CVE-2026-53661 — High (CVSS 8.8): Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized…
- CVE-2026-46398 — High (CVSS 8.8): HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version…
- CVE-2025-53757 — High (CVSS 8.7): This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on…
- CVE-2025-0479 — High (CVSS 8.6): This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface.…
- CVE-2024-2493 — High (CVSS 7.5): Session Hijacking vulnerability in Hitachi Ops Center Analyzer.This issue affects Hitachi Ops Center Analyzer: from…