CVE-2025-3744: Hashicorp Nomad
High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.
Affected products
- Hashicorp Nomad: before 1.8.13 (fixed in 1.8.13); from 1.9.0, before 1.9.9 (fixed in 1.9.9); version 1.10.0 only
Published 2025-05-13. Last modified 2026-06-17.