CVE-2026-48025 | forgekeep nebula-mesh up to 0.3.6 PKI ca.go Sign missing encryption

SecurityVulns

A vulnerability identified as problematic has been detected in forgekeep nebula-mesh up to 0.3.6. Affected by this issue is the function Sign of the file internal/pki/resolver.go/internal/pki/ca.go of the component PKI. The manipulation leads to missing encryption of sensitive data.

This vulnerability is referenced as CVE-2026-48025. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More