VYPR
High severity7.6NVD Advisory· Published May 13, 2025· Updated Jun 17, 2026

CVE-2025-3744

CVE-2025-3744

Description

Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Hashicorp/Nomad4 versions
    cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*+ 3 more
    • cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*range: <1.8.13
    • cpe:2.3:a:hashicorp:nomad:1.10.0:-:*:*:enterprise:*:*:*
    • cpe:2.3:a:hashicorp:nomad:1.10.0:beta1:*:*:enterprise:*:*:*
    • cpe:2.3:a:hashicorp:nomad:1.10.0:rc1:*:*:enterprise:*:*:*
  • Hashicorp/Nomad Enterprisellm-fuzzy2 versions
    up to 1.10.1, 1.9.9, and 1.8.13+ 1 more
    • (no CPE)range: up to 1.10.1, 1.9.9, and 1.8.13
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.