CVE-2026-25793

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:slack:nebula:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:25

Type Values Removed Values Added
Summary
  • (es) Nebula es una herramienta de red superpuesta escalable. En las versiones de 1.7.0 a 1.10.2, al usar certificados P256 (lo cual no es la configuración predeterminada), es posible evadir una entrada en la lista de bloqueo creada contra la huella digital de un certificado al usar la Maleabilidad de la Firma ECDSA para usar una copia del certificado con una huella digital diferente. Este problema ha sido parcheado en la versión 1.10.3.

18 Feb 2026, 17:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CPE cpe:2.3:a:slack:nebula:*:*:*:*:*:*:*:*
First Time Slack
Slack nebula
References () https://github.com/slackhq/nebula/commit/f573e8a26695278f9d71587390fbfe0d0933aa21 - () https://github.com/slackhq/nebula/commit/f573e8a26695278f9d71587390fbfe0d0933aa21 - Patch
References () https://github.com/slackhq/nebula/security/advisories/GHSA-69x3-g4r3-p962 - () https://github.com/slackhq/nebula/security/advisories/GHSA-69x3-g4r3-p962 - Vendor Advisory

06 Feb 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 23:15

Updated : 2026-06-17 10:25


NVD link : CVE-2026-25793

Mitre link : CVE-2026-25793

CVE.ORG link : CVE-2026-25793


JSON object : View

Products Affected

slack

  • nebula
CWE
CWE-347

Improper Verification of Cryptographic Signature