{"schema_version":"1.7.3","id":"GHSA-69x3-g4r3-p962","published":"2026-02-06T20:05:35Z","modified":"2026-02-21T01:58:57.299082Z","aliases":["CVE-2026-25793","GO-2026-4458"],"related":["CGA-frwm-cmv5-pf55"],"summary":"Blocklist Bypass possible via ECDSA Signature Malleability","details":"### Impact\n\nWhen using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint.\n\nIn order for this to affect a user or network, all of the following must be true:\n* `CURVE_P256` certificates are being used\n* There are one or more entries on the blocklist\n* The certificates for those entries are signed by a trusted CA and not expired\n* An attacker has a copy of the private key, and corresponding certificate, for one of those blocklist entries\n\n### Patches\n\nSee attached\n\n### Workarounds\n\nIf full copies of each certificate on the existing blocklist are available, it is possible to compute their opposite-chirality signature, and then the appropriate second fingerprint to list in the blocklist.\n\nRotating out all CAs that have signed hosts on the blocklist will also prevent exploitation of this vulnerability.","affected":[{"package":{"name":"github.com/slackhq/nebula","ecosystem":"Go","purl":"pkg:golang/github.com/slackhq/nebula"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.7.0"},{"fixed":"1.10.3"}]}],"database_specific":{"last_known_affected_version_range":"<= 1.10.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-69x3-g4r3-p962/GHSA-69x3-g4r3-p962.json"}}],"references":[{"type":"WEB","url":"https://github.com/slackhq/nebula/security/advisories/GHSA-69x3-g4r3-p962"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25793"},{"type":"WEB","url":"https://github.com/slackhq/nebula/commit/f573e8a26695278f9d71587390fbfe0d0933aa21"},{"type":"PACKAGE","url":"https://github.com/slackhq/nebula"}],"database_specific":{"cwe_ids":["CWE-347"],"github_reviewed":true,"github_reviewed_at":"2026-02-06T20:05:35Z","nvd_published_at":"2026-02-06T23:15:54Z","severity":"HIGH"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}