Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25793

Опубликовано: 06 фев. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:slack:nebula:*:*:*:*:*:*:*:*
Версия от 1.7.0 (включая) до 1.10.3 (исключая)

EPSS

Процентиль: 1%
0.00007
Низкий

8.1 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 8.1
redhat
около 2 месяцев назад

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.

github
около 2 месяцев назад

Blocklist Bypass possible via ECDSA Signature Malleability

EPSS

Процентиль: 1%
0.00007
Низкий

8.1 High

CVSS3

Дефекты

CWE-347