Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4jj9-cgqc-x9h5 | NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM) |
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suse
Suse neuvector |
|
| Vendors & Products |
Suse
Suse neuvector |
Thu, 08 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Jan 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks. | |
| Title | NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM) | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-01-08T14:56:07.901Z
Reserved: 2025-11-19T08:52:54.076Z
Link: CVE-2025-66001
Updated: 2026-01-08T14:56:04.841Z
Status : Deferred
Published: 2026-01-08T11:15:43.457
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-66001
No data.
OpenCVE Enrichment
Updated: 2026-01-09T13:25:39Z
Github GHSA