Security Advisories and CVEs
NeuVector is committed to informing the community about security issues. The following table lists published security advisories and CVEs (Common Vulnerabilities and Exposures) for resolved issues.
| ID | Description | Date | Resolution |
|---|---|---|---|
In the patched version, new NeuVector deployments enable TLS verification by default. For rolling upgrades, NeuVector does not change this setting automatically to avoid disruption. |
12 Dec 2025 |
||
NeuVector uses dynamically generated encryption keys and securely stores them in Kubernetes secrets. This improvement replaces previously hardcoded cryptographic material, enhancing data confidentiality and operational security in all deployments. |
17 Oct 2025 |
||
NeuVector enforces TLS certificate and hostname verification for all telemetry communications. In addition, it limits telemetry response size to prevent denial-of-service risks. These enhancements ensure telemetry data is exchanged securely and efficiently. |
17 Oct 2025 |
||
NeuVector strengthened the enforcer’s monitor process by validating environment variables before execution. This change prevents unsafe command execution and improves overall runtime security and process integrity. |
17 Oct 2025 |
||
For NeuVector deployments on Kubernetes-based environments, the bootstrap password of the default admin user is now generated randomly and stored in a Kubernetes secret. The default admin must retrieve the bootstrap password from the secret and change it after the first successful UI login. |
25 Aug 2025 |
||
NeuVector now uses a cryptographically secure salt with the PBKDF2 algorithm instead of a simple hash to protect user passwords. During rolling upgrades from earlier versions, NeuVector recalculates and stores the new password hash after each user’s next successful login. |
25 Aug 2025 |
||
NeuVector now redacts process commands containing |
25 Aug 2025 |
||
Sensitive information may be logged in the manager container depending on logging configuration and credential permissions. |
09 Jul 2025 |
||
In .NET, a malicious X.509 certificate or chain can cause excessive CPU use, leading to denial of service. This CVE was flagged as an affected .NET library detection issue. |
9 Jul 2024 |
||
The NGINX |
14 Aug 2024 |
||
In the GNU C Library through 2.29, |
15 Jan 2025 |
Not applicable. Flagged in v5.4.2 as a false positive. |
|
A security vulnerability in some Docker Engine versions may allow an attacker to bypass authorization plugins (AuthZ). The likelihood of exploitation is low. |
16 Nov 2024 |
||
|
16 Nov 2024 |
Questions and Support
-
Contact the SUSE Rancher Security team.
-
Open an issue in the NeuVector GitHub repository.
-
References: