CVE-2026-25793

Description

A flaw was found in Nebula, a scalable overlay networking tool. When configured to use P256 certificates, an attacker can exploit Elliptic Curve Digital Signature Algorithm (ECDSA) Signature Malleability. This allows the attacker to create a modified copy of a certificate with a different fingerprint, thereby evading existing blocklist entries. This could lead to unauthorized network access or bypass of security controls.

Statement

While the flaw is rated as Important, please keep in mind that there are several preconditions that must be true for a customer to be impacted:

  1. They must be used CURVE_P256 certificates (which are not the default).
  2. They must have one or more entries on their blocklist.
  3. The certificates of those blocklisted entries must be signed by a trusted CA and not expired.
  4. An attacker must have a copy of the private key and corresponding certificate for one of those blocklist entries.

Mitigation

Avoid configuring Nebula to use P256 certificates. This vulnerability is only exploitable when P256 certificates are explicitly enabled, as they are not the default configuration. Ensure Nebula deployments utilize default or other non-P256 certificate types to prevent blocklist evasion.

Understanding the Weakness (CWE)

Access Control,Integrity,Confidentiality

Technical Impact: Gain Privileges or Assume Identity; Modify Application Data; Execute Unauthorized Code or Commands

An attacker could gain access to sensitive data and possibly execute unauthorized code.

Frequently Asked Questions

Want to get errata notifications? Sign up here.