← back
CVE-2025-0937highCWE-863

Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.1epss 0.4%
exploitation probability
0.4%top 62% of all CVEs
observed exploitation
nono source reports it
Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N