Slack
Slack Nebula: vulnerabilities and CVEs
Slack Nebula has 6 published vulnerabilities, 5 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months5
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61699 | High (8.1) | 0.45% | — | Sep 4, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the… |
| CVE-2026-53604 | High (7.1) | 0.18% | — | Sep 4, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build,… |
| CVE-2026-74238 | High (8.7) | 0.48% | — | Aug 17, 2026 | TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP… |
| CVE-2026-25793 | High (7.6) | 0.17% | — | Feb 6, 2026 | Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the… |
| CVE-2025-62820 | Medium (4.9) | 0.22% | — | Oct 23, 2025 | Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network. |
| CVE-2020-11498 | High (8.8) | 3.4% | — | Apr 2, 2020 | Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to… |