CVE-2026-53602: nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate
Two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate issuance time — only at poll time.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-53602 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →