Nesos crosses Linux namespace and privilege boundaries, so security reports are taken seriously.
Please do not open a public issue. Use GitHub's private vulnerability reporting to contact the maintainers privately.
Include the affected revision or version, Linux distribution and kernel version, reproduction steps, observed impact, and any suggested mitigation. Avoid including secrets or data belonging to other people.
Before 1.0, security fixes target the latest release and the main branch. Older
pre-1.0 releases may require upgrading rather than receiving a backport.
The bridge broker always protects its control connection with TLS. That does not make
raw VXLAN an authenticated or encrypted data plane. A VXLAN offer must explicitly
classify its underlay as protected or unsafe; unsafe use also requires a client
acknowledgement. Prefer the WireGuard transport across routed or untrusted locations,
which carries VXLAN inside an authenticated encrypted tunnel. See the
traffic and bridge guide
for the policy and key-handling model.