CVE-2025-1296: Hashicorp Nomad
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.
Affected products
- Hashicorp Nomad: from 1.0.0, before 1.7.19 (fixed in 1.7.19); from 1.0.0, before 1.9.7 (fixed in 1.9.7); from 1.8.0, before 1.8.11 (fixed in 1.8.11); from 1.9.0, before 1.9.7 (fixed in 1.9.7)
Published 2025-03-10. Last modified 2026-06-17.