Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs in github.com/hashicorp/nomad
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2025-3510" }