CVE-2026-48058CWE-614

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

Medium · published July 28, 2026

CVSS v4.0
4.6
EPSS
0%
Percentile
9.1
In the wild
Unconfirmed
What it is

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session. This issue has been patched in version 0.3.2.

The record
Technical detail
CVSS v4.0
4.6 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
EPSS
0.00193 · 9.1th percentile
Weakness
CWE-614 · Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Published
2026-07-28T18:47Z
EPSS history
Timeline
  • 28 JUL 18:47Z
    nebula-mesh: Session and OIDC state cookies lack the Secure attribute
    cvelistv5