A vulnerability was found in forgekeep nebula-mesh up to 0.3.1. It has been classified as problematic. This vulnerability affects unknown code of the file internal/web/session.go/internal/web/oidc.go. The manipulation leads to cleartext transmission of sensitive information.

This vulnerability is traded as CVE-2026-48058. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.