nebula-mesh: CA Private Key Exposure via Unzeroized Memory
A vulnerability in nebula-mesh (CVE-2026-53604, CVSS 8.7) exposes the CA private key in memory due to improper zeroization on error paths in the web UI's mobile-bundle handling. This allows an attacker with process memory access to recover the key and mint arbitrary host certificates. Affected versions are <= 0.3.7; patch to version 0.3.8 or later.