Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.
| Software | From | Fixed in |
|---|---|---|
| hashicorp / nomad | - | 1.8.13 |
| hashicorp / nomad | 1.9.0 | 1.9.9 |
| hashicorp / nomad | 1.10.0 | 1.10.0.x |
| hashicorp / nomad | 1.10.0-beta1 | 1.10.0-beta1.x |
| hashicorp / nomad | 1.10.0-rc1 | 1.10.0-rc1.x |