CVE-2025-66001

HIGH

NeuVector - Info Disclosure

Title source: llm
STIX 2.1

Description

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.

Scores

CVSS v3 8.8
EPSS 0.0003
EPSS Percentile 9.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (2)
neuvector/neuvector 5.3.0 - 5.4.8Go
SUSE/neuvector 5.3.0 - 5.4.8
Published Jan 08, 2026
Tracked Since Feb 18, 2026