CVE-2026-25793General(slack / nebula)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch slack nebula systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nebula

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-06); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
nebula

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-12: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-12: 102-0602-0802-0902-12
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-061
General1
2026-02-081
General1
2026-02-091
Disclosure1
2026-02-121
General1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25793 Certificate Fingerprint Bypass Vulnerability in NebUla Overlayays 1.7.0-10.2 Human Human title https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25793

    Post summary

    The text mentions CVE-2026-25793, a certificate fingerprint bypass vulnerability in NebUla Overlayays 1.7.0-10.2, but offers only minimal technical details without further context or actionable information.

    0001030
    4.0K followersView on X
  • Imran@mrtufan0x01
    Disclosure

    🚨 New CVE Discovered! ​CVE-2026-25793 assigned for a Blocklist Bypass in @SlackHQ's Nebula overlay network. 🛡️ ​By exploiting ECDSA Signature Malleability, it was possible to evade security controls on affected versions. 📉 ​Severity: High (8.1) 🔴 Fixed in v1.10.3. Update now! ​🔗 Advisory: https://github.com/slackhq/nebula/security/advisories/GHSA-69x3-g4r3-p962 ​#BugBounty #InfoSec #Cryptography #NetworkSecurity #Slack

    Post summary

    A newly discovered CVE (CVE‑2026‑25793) exposes a blocklist bypass in Slack’s Nebula through ECDSA malleability; it is rated high severity (8.1) and is fixed in version 1.10.3 with a public advisory available.

    0000071
    31 followersView on X
  • cvereports@_cvereports
    General

    CVE-2026-25793: Doppelgänger Certificates: Bypassing Nebula Blocklists with ECDSA Magic In the world of cryptography, two things can be mathematically identical yet look completely different to a computer. CVE-2026-25793 is a fascinating logic flaw in... https://cvereports.com/reports/CVE-2026-25793

    Post summary

    The brief post mentions CVE-2026-25793 as a cryptographic logic flaw, but provides no specific exploit details, patches, or evidence of active exploitation.

    0000042
    27 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25793 Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible … https://www.cve.org/CVERecord?id=CVE-2026-25793

    Post summary

    The text briefly references CVE-2026-25793, noting a potential issue when using P256 certificates in certain Nebula versions, but offers no detailed technical or remedial information.

    00000193
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appslacknebula---

Explore more