CVE-2025-3744: Hashicorp Nomad

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.

Affected products

  • Hashicorp Nomad: before 1.8.13 (fixed in 1.8.13); from 1.9.0, before 1.9.9 (fixed in 1.9.9); version 1.10.0 only

Published 2025-05-13. Last modified 2026-06-17.