CVE-2025-0937: Hashicorp Nomad
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.
Affected products
- Hashicorp Nomad: from 1.0.0, before 1.7.18 (fixed in 1.7.18); from 1.0.0, before 1.9.6 (fixed in 1.9.6); from 1.8.0, before 1.8.10 (fixed in 1.8.10); from 1.9.0, before 1.9.6 (fixed in 1.9.6)
Published 2025-02-12. Last modified 2026-06-17.