CVE-2026-63464 | Forgekeep Nebula Mesh up to 0.7.1 Webhook Subscription webhook-subscriptions allow_private server-side request forgery

SecurityVulns

A vulnerability was found in Forgekeep Nebula Mesh up to 0.7.1. It has been rated as critical. This issue affects some unknown processing of the file /api/v1/webhook-subscriptions of the component Webhook Subscription. The manipulation of the argument allow_private leads to server-side request forgery.

This vulnerability is documented as CVE-2026-63464. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More