PT-2025-43432 · Slack · Slack Nebula

CVE-2025-62820

·

Published

2025-10-23

·

Updated

2026-07-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slack Nebula versions prior to 1.9.7
Description Slack Nebula, in some configurations, does not properly handle CIDR (Classless Inter-Domain Routing) notation. This allows for the acceptance of arbitrary source IP addresses within the Nebula network.
Recommendations Update to version 1.9.7 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-CE02533
CLEANSTART-2026-CV29689
CLEANSTART-2026-DK89443
CLEANSTART-2026-KC01126
CLEANSTART-2026-KV78041
CLEANSTART-2026-MI26039
CLEANSTART-2026-OL60454
CLEANSTART-2026-UZ79996
CLEANSTART-2026-WX54555
CVE-2025-62820
GHSA-X6FH-7QMF-69XH
GO-2025-4068
OPENSUSE-SU-2025:15710-1
OPENSUSE-SU-2026:21483-1

Affected Products

Slack Nebula