CVE-2025-62820: Medium severity Slack Nebula vulnerability
Published Oct 23, 2025
·Updated
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
Affected Software
2 affected componentsFixes available
Slack Nebula<1.9.7
go/github.com/slackhq/nebula>=1.9.4<1.9.7
1.9.7
Event History
Oct 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:31 AM
Data Sourced
via GitHub·06:31 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62820?
CVE-2025-62820 is classified as a critical vulnerability due to its potential to allow arbitrary source IP addresses within the Nebula network.
2
How do I fix CVE-2025-62820?
To fix CVE-2025-62820, upgrade Slack Nebula to version 1.9.7 or later.
3
What impact does CVE-2025-62820 have on Slack Nebula?
CVE-2025-62820 can allow unauthorized access by accepting arbitrary source IP addresses in certain configurations.
4
In which versions of Slack Nebula is CVE-2025-62820 present?
CVE-2025-62820 is present in all versions of Slack Nebula prior to 1.9.7.
5
How can I determine if I am affected by CVE-2025-62820?
You can determine if you are affected by CVE-2025-62820 by checking your version of Slack Nebula and ensuring it is 1.9.7 or newer.