CVE-2025-66001

Publication date

2026-01-08 10:23:18

Family

suse

State

PUBLISHED

Description

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote servers authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.