Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.8.13"
},
{
"introduced": "1.9.0"
},
{
"fixed": "1.9.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.10.0-NA"
}
]
}