Junglewise Threat Intelligence

CVE-2025-54470: SUSE NeuVector MITM and DoS in telemetry sender

CVE-2025-54470 · Severity: high · CVSS 8.6 · Published 2025-10-21

Technologies: Suse NeuVector, github.com/neuvector/neuvector (Go). Vendors: Suse, Go.

Executive brief

NeuVector, a container security platform, contains vulnerabilities in its telemetry reporting component. If the anonymous data reporting feature is enabled, attackers could intercept or modify transmitted data or crash the service by sending an oversized response from a spoofed server. This could lead to a loss of service availability or the exposure of cluster metadata.

Technical details

NeuVector's telemetry sender component fails to enforce TLS certificate verification (CWE-295) when communicating with its remote telemetry server. A network-positioned attacker can perform a man-in-the-middle attack to intercept or modify anonymous cluster data. Furthermore, the component lacks size limits when loading server responses into memory (CWE-770), allowing an attacker to trigger a Denial of Service via memory exhaustion. These issues are resolved in version 5.4.7 by enforcing certificate chain/hostname verification and implementing a 256-byte response limit.

Affected products

  • SUSE NeuVector < v5.4.7

Timeline

  • 2025-10-21: advisory: Original GHSA advisory published
  • 2025-10-21: patched: Version 5.4.7 released with fixes

References

Related threats