github.com/slackhq/nebula
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/slackhq/nebulapage 1 of 1
- CVE-2025-62820MEDIUMCVSS 4.9EG 4.9✓ Fixed in 1.9.72025-10-23
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
- CVE-2026-25793HIGHCVSS 8.1EG 8.1✓ Fixed in 1.10.32026-02-06
Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certifica…
Check whether github.com/slackhq/nebula is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/slackhq/nebula CVEs against the assets you own.
Start Free Scan →