Executive brief
NeuVector, a container security platform, contains vulnerabilities in its telemetry reporting component. If the anonymous data reporting feature is enabled, attackers could intercept or modify transmitted data or crash the service by sending an oversized response from a spoofed server. This could lead to a loss of service availability or the exposure of cluster metadata.
Technical details
NeuVector's telemetry sender component fails to enforce TLS certificate verification (CWE-295) when communicating with its remote telemetry server. A network-positioned attacker can perform a man-in-the-middle attack to intercept or modify anonymous cluster data. Furthermore, the component lacks size limits when loading server responses into memory (CWE-770), allowing an attacker to trigger a Denial of Service via memory exhaustion. These issues are resolved in version 5.4.7 by enforcing certificate chain/hostname verification and implementing a 256-byte response limit.
Affected products
- SUSE NeuVector < v5.4.7
Timeline
- 2025-10-21: advisory: Original GHSA advisory published
- 2025-10-21: patched: Version 5.4.7 released with fixes