Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
{
"nvd_published_at": "2025-10-23T04:18:57Z",
"cwe_ids": [
"CWE-420"
],
"severity": "MODERATE",
"github_reviewed_at": "2025-10-23T16:49:07Z",
"github_reviewed": true
}