Skip to content
NomadGHSA-rx97-6c62-55mf

Hashicorp Nomad Incorrect Privilege Assignment vulnerability

High8.1CVE-2025-4922 · Published Jun 11, 2025 · updated Jul 28, 2025

Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
< 1.10.21.10.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266
Also known as
CVE-2025-4922, GO-2025-3758

More Nomad advisories

All Nomad
Advisory
HashiCorp Nomad vulnerable to a path traversal
High8.8May 12
Nomad: secrets in logs
Medium6.5Mar 10, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
Medium6.5Dec 20, 2024
Hashicorp Nomad Incorrect Authorization vulnerability
Medium7.7Nov 7, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking
Medium5.8Aug 15, 2024
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration
High7.7Jul 23, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.