VDB
GO-2026-4458
GO-2026-4458
PUBLISHED
Blocklist Bypass possible via ECDSA Signature Malleability in github.com/slackhq/nebula
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | step-issuer | 0, 0, 0 |
| wolfi | step-ca | 0, 0, 0 |
| chainguard | step-ca-fips | 0, 0, 0 |
| chainguard | step | 0, 0, 0 |
| wolfi | step | 0, 0, 0 |
| chainguard | step-ca | 0, 0, 0 |
| chainguard | caddy | 0, 0 |
| github.com | slackhq/nebula | 1.7.0, 1.7.0 |
| wolfi | caddy | 0, 0, 0 |
| chainguard | caddy-fips | 0, 0 |
| wolfi | step-issuer | 0, 0, 0 |
| chainguard | step-issuer-fips | 0, 0, 0 |
| chainguard | step-fips | 0, 0, 0 |
Timeline
- Feb 17, 2026 CVE Published
- Feb 21, 2026 CVE Updated
- May 1, 2026 Security Advisory