Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w7w5-5gcp-38rw | nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) |
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Content-Security-Policy`, `X-Frame-Options`, `Strict-Transport-Security`, `X-Content-Type-Options`, `Referrer-Policy` returns zero matches across the codebase. Version 0.3.1 fixes the issue. | |
| Title | nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) | |
| Weaknesses | CWE-1021 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-24T13:54:01.417Z
Reserved: 2026-05-19T21:29:25.482Z
Link: CVE-2026-47723
Updated: 2026-07-24T13:53:56.157Z
No data.
No data.
OpenCVE Enrichment
No data.
Github GHSA