CVE Vulnerabilities

CVE-2025-66001

Improper Certificate Validation

Published: Jan 08, 2026 | Modified: Jan 08, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote servers authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References