NomadGHSA-rx97-6c62-55mf
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
High8.1CVE-2025-4922 · Published Jun 11, 2025 · updated Jul 28, 2025
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | < 1.10.2 | 1.10.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-266
- Also known as
- CVE-2025-4922, GO-2025-3758
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 12 | HashiCorp Nomad vulnerable to a path traversal | High8.8 | 1.11.0-rc.1.0.20260511152149-cd7240c4099a |
| Mar 102025 | Nomad: secrets in logs | Medium6.5 | No fix yet |
| Dec 202024 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | Medium6.5 | 1.9.4 |
| Nov 72024 | Hashicorp Nomad Incorrect Authorization vulnerability | Medium7.7 | No fix yet |
| Aug 152024 | Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking | Medium5.8 | 1.6.14+2 more |
| Jul 232024 | HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration | High7.7 | 1.8.2 |