# CVE-2026-48058

## Summary

- **CVE ID:** CVE-2026-48058
- **Severity:** MEDIUM
- **CVSS Score:** 4.6 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U)
- **CWE:** CWE-614
- **Published:** Jul 28, 2026
- **Last Modified:** Jul 28, 2026

## Description

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session. This issue has been patched in version 0.3.2.

## Affected Products

- juev — nebula-mesh (< 0.3.2)

## References

- [CNA](https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-rqfj-vv8r-xhqc)
- [CNA](https://github.com/forgekeep/nebula-mesh/commit/ffdd67dbf221d9a5855c39fbe11b49c245048d85)
- [CNA](https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 9.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._