Junglewise Threat Intelligence

CVE-2025-71261: SUSE Harvester improper certificate validation in registration client

CVE-2025-71261 · Severity: high · CVSS 8.6 · Published 2026-06-16

Vendors: Go, Suse.

Executive brief

SUSE Harvester, a virtualization platform, contains a security flaw in how it connects to Rancher management servers. By default, the system fails to verify the identity of the server it is talking to, which could allow an attacker to intercept communications or crash the registration service. This could lead to a loss of control over cluster registration or a denial of service for the virtualization management interface.

Technical details

A vulnerability exists in the SUSE Virtualization (Harvester) Rancher integration mechanism where the registration client fails to verify remote server certificates (CWE-295). An attacker with network-level access between Harvester and the Rancher Manager can perform a Man-in-the-Middle (MitM) attack to intercept or impersonate cluster registration requests. Furthermore, the registration controller does not perform size validation on response payloads, allowing an attacker to trigger a memory buffer overflow and crash the service. This issue specifically affects the 'cluster-registration-url' setting and is resolved in version 1.8.0 by enforcing certificate validation against system root CAs.

Affected products

  • SUSE Harvester (SUSE Virtualization) < 1.8.0

Timeline

  • 2026-04-28: disclosed: Initial disclosure by maintainers
  • 2026-05-06: advisory: GitHub Advisory published
  • 2026-06-16: other: NVD published date

References