Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
Weakness
The product protects a primary channel, but it does not use the same level of protection for an alternate channel.
Potential Mitigations
References