NIXPKGS-2026-0140
GitHub issue
published 7 months ago
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
7 packages
- nebula-sans
- ant-nebula-theme
- nebula-lighthouse-service
- terraform-providers.opennebula
- python312Packages.nebula3-python
- terraform-providers.opennebula_opennebula
- python312Packages.llama-index-graph-stores-nebula
- @LeSuisse accepted
- @LeSuisse published on GitHub
Nebula Has Possible Blocklist Bypass via ECDSA Signature Malleability
Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.
References
Affected products
nebula
- ==>= 1.7.0, < 1.10.3
Matching in nixpkgs
Ignored packages (7)
pkgs.nebula-sans
Versatile, modern, humanist sans-serif with a neutral aesthetic, designed for legibility in both digital and print applications
pkgs.ant-nebula-theme
Nebula variant of the Ant theme
pkgs.nebula-lighthouse-service
Public Nebula VPN Lighthouse Service
pkgs.terraform-providers.opennebula
None
pkgs.python312Packages.nebula3-python
None
Package maintainers
-
@numinit Morgan Jones <me+nixpkgs@numin.it>