We found results for “”
CVE-2025-62820
Good to know:
Date: October 22, 2025
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Unprotected Alternate Channel
CWE-420Top Fix
Upgrade Version
Upgrade to version github.com/slackhq/nebula - v1.9.7;github.com/slackhq/nebula - v1.9.7
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | LOW |
Vulnerabilities
Projects
Contact Us


