Activity log
- Created suggestion
Nebula Has Possible Blocklist Bypass via ECDSA Signature Malleability
Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.
References
Affected products
- ==>= 1.7.0, < 1.10.3
Matching in nixpkgs
pkgs.nebula
Overlay networking tool with a focus on performance, simplicity and security
pkgs.nebula-sans
Versatile, modern, humanist sans-serif with a neutral aesthetic, designed for legibility in both digital and print applications
pkgs.ant-nebula-theme
Nebula variant of the Ant theme
pkgs.nebula-lighthouse-service
Public Nebula VPN Lighthouse Service
pkgs.terraform-providers.opennebula
None
-
nixos-unstable 1.5.0
pkgs.python312Packages.nebula3-python
Client API of Nebula Graph in Python
-
nixos-unstable nebula3-python-3.8.3
-
nixos-25.11 nebula3-python-3.8.3
- nixpkgs-25.11-darwin nebula3-python-3.8.3
pkgs.python312Packages.llama-index-graph-stores-nebula
LlamaIndex Graph Store Integration for Nebula
-
nixos-unstable 0.4.2
Package maintainers
-
@alexarice Alex Rice <alexrice999@hotmail.co.uk>
-
@Br1ght0ne Oleksii Filonenko <brightone@protonmail.com>
-
@numinit Morgan Jones <me+nixpkgs@numin.it>
-
@colemickens Cole Mickens <cole.mickens@gmail.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@bloominstrong bloominstrong <github@mail.bloominstrong.net>