Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x6fh-7qmf-69xh | Slack Nebula may accept arbitrary source IP addresses |
Thu, 23 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Slack
Slack nebula |
|
| Vendors & Products |
Slack
Slack nebula |
Thu, 23 Oct 2025 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network. | |
| Weaknesses | CWE-420 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-23T14:35:19.815Z
Reserved: 2025-10-23T00:00:00.000Z
Link: CVE-2025-62820
Updated: 2025-10-23T13:26:22.210Z
Status : Deferred
Published: 2025-10-23T04:18:57.453
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-62820
No data.
OpenCVE Enrichment
Updated: 2025-10-23T09:58:37Z
Github GHSA