CVE-2026-25793: Nebula Has Possible Blocklist Bypass via ECDSA Signature Malleability

Published Feb 6, 2026
·
Updated

Impact

When using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint.

In order for this to affect a user or network, all of the following must be true: CURVEP256 certificates are being used There are one or more entries on the blocklist The certificates for those entries are signed by a trusted CA and not expired An attacker has a copy of the private key, and corresponding certificate, for one of those blocklist entries

Patches

See attached

Workarounds

If full copies of each certificate on the existing blocklist are available, it is possible to compute their opposite-chirality signature, and then the appropriate second fingerprint to list in the blocklist.

Rotating out all CAs that have signed hosts on the blocklist will also prevent exploitation of this vulnerability.

Other sources

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.

MITRE

Affected Software

2 affected componentsFixes available
go/github.com/slackhq/nebula>=1.7.0<=1.10.2
1.10.3
Slack Nebula>=1.7.0<1.10.3

Event History

Feb 6, 2026
Advisory Published
via GitHub·08:05 PM
Data Sourced
via GitHub·08:05 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-25793?

CVE-2026-25793 has a moderate severity level due to the potential for certificate fingerprint evasion.

2

How do I fix CVE-2026-25793?

To fix CVE-2026-25793, upgrade to version 1.10.3 or later of the affected software.

3

Which software is affected by CVE-2026-25793?

CVE-2026-25793 affects versions 1.7.0 to 1.10.2 of the Nebula software from Slack.

4

What vulnerability does CVE-2026-25793 address?

CVE-2026-25793 addresses ECDSA Signature Malleability in P256 certificates, allowing blocklist evasion.

5

Is CVE-2026-25793 exploitable under default configurations?

No, CVE-2026-25793 is only exploitable when using P256 certificates, which is not the default configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203