NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.
References
Configurations
No configuration.
History
08 Jan 2026, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-08 11:15
Updated : 2026-01-08 18:08
NVD link : CVE-2025-66001
Mitre link : CVE-2025-66001
CVE.ORG link : CVE-2025-66001
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation
