<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:47:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-342193</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342193</link>
      <description>EUVD-2026-342193</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342193</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48058</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48058</link>
      <description>&lt;p&gt;nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session. This issue has been patched in version 0.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on every cookie but never Secure. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session. This issue has been patched in version 0.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48058</guid>
    </item>
    <item>
      <title>GHSA-rqfj-vv8r-xhqc — nebula-mesh: Session and OIDC state cookies lack the Secure attribute</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rqfj-vv8r-xhqc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/juev/nebula-mesh&lt;/p&gt;
&lt;p&gt;`internal/web/session.go` and `internal/web/oidc.go` set `HttpOnly` and `SameSite=Lax` on every cookie but never `Secure`. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session.&lt;/p&gt;
&lt;p&gt;## Affected
All released versions up to v0.3.1.&lt;/p&gt;
&lt;p&gt;## Impact
An attacker who can observe one HTTP request to the origin recovers the session cookie and impersonates the operator for the remainder of its 24h TTL. The OIDC state cookie has a narrower 10-minute window but enables CSRF on the OIDC callback during that window.&lt;/p&gt;
&lt;p&gt;## Cookie sites
- `internal/web/session.go` — `Login`, `StartAuthenticatedSession`, `CompleteTwoFactor`, `Logout`
- `internal/web/oidc.go` — `HandleLogin` (state set), `HandleCallback` (state clear)&lt;/p&gt;
&lt;p&gt;## Suggested fix
Driven by an explicit `cookie_secure` config option, inferred true when `tls_cert`+`tls_key` are configured and false otherwise. `rate_limit.trust_proxy_header` is deliberately not used as a signal — that flag controls XFF parsing for rate-limit IPs and does not promise the proxy speaks TLS to clients. Operator behind a TLS-terminating proxy sets `cookie_secure: true` explicitly.&lt;/p&gt;
&lt;p&gt;Logout and OIDC state-clear cookies also pick up matching `HttpOnly` + `SameSite=Lax` so browsers reliably replace the original.&lt;/p&gt;
&lt;p&gt;## Reproducer
Start `nebula-mgmt` without `tls_cert`/`tls_key` (the documented &amp;#34;behind a reverse proxy&amp;#34; deployment). Hit any login flow over the local listen…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/juev/nebula-mesh&lt;/p&gt;
&lt;p&gt;`internal/web/session.go` and `internal/web/oidc.go` set `HttpOnly` and `SameSite=Lax` on every cookie but never `Secure`. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session.&lt;/p&gt;
&lt;p&gt;## Affected
All released versions up to v0.3.1.&lt;/p&gt;
&lt;p&gt;## Impact
An attacker who can observe one HTTP request to the origin recovers the session cookie and impersonates the operator for the remainder of its 24h TTL. The OIDC state cookie has a narrower 10-minute window but enables CSRF on the OIDC callback during that window.&lt;/p&gt;
&lt;p&gt;## Cookie sites
- `internal/web/session.go` — `Login`, `StartAuthenticatedSession`, `CompleteTwoFactor`, `Logout`
- `internal/web/oidc.go` — `HandleLogin` (state set), `HandleCallback` (state clear)&lt;/p&gt;
&lt;p&gt;## Suggested fix
Driven by an explicit `cookie_secure` config option, inferred true when `tls_cert`+`tls_key` are configured and false otherwise. `rate_limit.trust_proxy_header` is deliberately not used as a signal — that flag controls XFF parsing for rate-limit IPs and does not promise the proxy speaks TLS to clients. Operator behind a TLS-terminating proxy sets `cookie_secure: true` explicitly.&lt;/p&gt;
&lt;p&gt;Logout and OIDC state-clear cookies also pick up matching `HttpOnly` + `SameSite=Lax` so browsers reliably replace the original.&lt;/p&gt;
&lt;p&gt;## Reproducer
Start `nebula-mgmt` without `tls_cert`/`tls_key` (the documented &amp;#34;behind a reverse proxy&amp;#34; deployment). Hit any login flow over the local listen…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rqfj-vv8r-xhqc</guid>
    </item>
  </channel>
</rss>
