Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25793

Опубликовано: 06 фев. 2026
Источник: nvd
EPSS Низкий

Описание

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.

EPSS

Процентиль: 3%
0.00017
Низкий

Дефекты

CWE-347

Связанные уязвимости

github
2 дня назад

Blocklist Bypass possible via ECDSA Signature Malleability

EPSS

Процентиль: 3%
0.00017
Низкий

Дефекты

CWE-347