Security Advisories and CVEs
NeuVector is committed to informing the community about security issues. The following table lists published security advisories and CVEs (Common Vulnerabilities and Exposures) for resolved issues.
CVE List
| ID | Description | Date | Resolution |
|---|---|---|---|
Fixed a security vulnerability where improper parameter handling allowed any authenticated users access to inject OS commands in the privileged enforcer container, which could lead to the complete compromise of the worker node. |
15 September 2026 |
||
Fixed a security vulnerability regarding improper authentication where starting from version v5.6.2, users can configure the “Audience URI” in the Settings → SAML Settings page. After the “Audience URI” is configured, it is used and checked during SAML SSO so that assertion for other applications won’t be accepted by SUSE Security. |
15 September 2026 |
||
Fixed a security vulnerability where the SUSE Security JWT verifier accepted non-canonical |
15 September 2026 |
||
Fixed a security vulnerability where the SUSE Security admission webhook silently excluded containers from policy evaluation when their image path matched one of three hard-coded service mesh sidecar images. This could lead malicious users to deploy workloads by evading admission deny rules by naming their image path after one of these sidecar images. Starting from version v5.6.2, the automatic sidecar exemptions are removed entirely. |
15 September 2026 |
||
Fixed a security vulnerability for users that authenticated through SAML or OpenID Connect (OIDC). This vulnerability would result in one user receiving another user’s authenticated session when multiple SSO login attempts occurred concurrently. |
15 September 2026 |
Questions and Support
-
Contact the SUSE Rancher Security team.
-
Open an issue in the NeuVector GitHub repository.
-
References: