CVE-2025-66001

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.
Configurations

No configuration.

History

08 Jan 2026, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-08 11:15

Updated : 2026-01-08 18:08


NVD link : CVE-2025-66001

Mitre link : CVE-2025-66001

CVE.ORG link : CVE-2025-66001


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation