Security Advisories and CVEs
NeuVector is committed to informing the community about security issues. The following table lists published security advisories and CVEs (Common Vulnerabilities and Exposures) for resolved issues.
| ID | Description | Date | Resolution |
|---|---|---|---|
Fixed a security vulnerability where improper parameter handling allowed any authenticated users access to inject OS commands in the privileged enforcer container, which could lead to the complete compromise of the worker node. |
15 September 2026 |
||
Fixed a security vulnerability regarding improper authentication where starting from version v5.6.2, users can configure the “Audience URI” in the Settings → SAML Settings page. After the “Audience URI” is configured, it is used and checked during SAML SSO so that assertion for other applications won’t be accepted by SUSE Security. |
15 September 2026 |
||
Fixed a security vulnerability where the SUSE Security JWT verifier accepted non-canonical |
15 September 2026 |
||
Fixed a security vulnerability where the SUSE Security admission webhook silently excluded containers from policy evaluation when their image path matched one of three hard-coded service mesh sidecar images. This could lead malicious users to deploy workloads by evading admission deny rules by naming their image path after one of these sidecar images. Starting from version v5.6.2, the automatic sidecar exemptions are removed entirely. |
15 September 2026 |
||
Fixed a security vulnerability for users that authenticated through SAML or OpenID Connect (OIDC). This vulnerability would result in one user receiving another user’s authenticated session when multiple SSO login attempts occurred concurrently. |
15 September 2026 |
||
In the patched version, new NeuVector deployments enable TLS verification by default. For rolling upgrades, NeuVector does not change this setting automatically to avoid disruption. |
12 Dec 2025 |
||
NeuVector uses dynamically generated encryption keys and securely stores them in Kubernetes secrets. This improvement replaces previously hardcoded cryptographic material, enhancing data confidentiality and operational security in all deployments. |
17 Oct 2025 |
||
NeuVector enforces TLS certificate and hostname verification for all telemetry communications. In addition, it limits telemetry response size to prevent denial-of-service risks. These enhancements ensure telemetry data is exchanged securely and efficiently. |
17 Oct 2025 |
||
NeuVector strengthened the enforcer’s monitor process by validating environment variables before execution. This change prevents unsafe command execution and improves overall runtime security and process integrity. |
17 Oct 2025 |
||
For NeuVector deployments on Kubernetes-based environments, the bootstrap password of the default admin user is now generated randomly and stored in a Kubernetes secret. The default admin must retrieve the bootstrap password from the secret and change it after the first successful UI login. |
25 Aug 2025 |
||
NeuVector now uses a cryptographically secure salt with the PBKDF2 algorithm instead of a simple hash to protect user passwords. During rolling upgrades from earlier versions, NeuVector recalculates and stores the new password hash after each user’s next successful login. |
25 Aug 2025 |
||
NeuVector now redacts process commands containing |
25 Aug 2025 |
||
Sensitive information may be logged in the manager container depending on logging configuration and credential permissions. |
09 Jul 2025 |
||
In .NET, a malicious X.509 certificate or chain can cause excessive CPU use, leading to denial of service. This CVE was flagged as an affected .NET library detection issue. |
9 Jul 2024 |
||
The NGINX |
14 Aug 2024 |
||
In the GNU C Library through 2.29, |
15 Jan 2025 |
Not applicable. Flagged in v5.4.2 as a false positive. |
|
A security vulnerability in some Docker Engine versions may allow an attacker to bypass authorization plugins (AuthZ). The likelihood of exploitation is low. |
16 Nov 2024 |
||
|
16 Nov 2024 |
Questions and Support
-
Contact the SUSE Rancher Security team.
-
Open an issue in the NeuVector GitHub repository.
-
References: