Junglewise Threat Intelligence

CVE-2026-47768: juev nebula-mesh API key exposure via sensitive query strings

CVE-2026-47768 · Severity: medium · CVSS 5.5 · Published 2026-07-28

Technologies: Juev Nebula-Mesh, github.com/juev/nebula-mesh (Go). Vendors: Forgekeep, Go.

Executive brief

nebula-mesh is a management tool for Slack Nebula virtual private networks. A security flaw in the administrative interface causes newly created API keys to be included directly in the web browser's address bar during a redirect. This results in sensitive credentials being recorded in browser history, server logs, and potentially shared with third-party websites via web headers, allowing anyone with access to those logs to impersonate an administrator.

Technical details

The vulnerability exists in `internal/web/operators.go` within the `handleOperatorCreateAPIKey` function. When a new 32-byte bearer token is generated, the application issues a 303 redirect that includes the raw API key as a query parameter (`new_key`). This violates secure coding practices by placing sensitive credentials in the URL, where they are captured by browser history, reverse-proxy access logs (like Nginx), and transmitted in the `Referer` header to any cross-origin assets loaded on the subsequent page. Additionally, the `name` parameter was found to be missing proper URL encoding, potentially allowing for query string corruption. The issue is addressed in version 0.3.2 by removing the key from the redirect URL.

Affected products

  • juev nebula-mesh < 0.3.2

Timeline

  • 2026-05-21: patched: Version 0.3.2 released
  • 2026-05-21: advisory: GitHub Security Advisory GHSA-9pg3-25fq-p6cc published
  • 2026-07-28: disclosed: CVE-2026-47768 published to NVD

References

Related threats