---
id: CVE-2025-54470
title: >-
  This vulnerability affects NeuVector deployments only when the Report
  anonymous cluster data option is enabled
summary: >-
  This vulnerability affects NeuVector deployments only when the Report
  anonymous cluster data option is enabled. When this option is enabled,
  NeuVector sends anonymous telemetry data to the telemetry server.



  In affected versions, NeuVec…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'
cwe:
  - CWE-295
published: '2025-10-30'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54470'
references:
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-54470'
    label: meissner@suse.de
  - url: >-
      https://github.com/neuvector/neuvector/security/advisories/GHSA-qqj3-g7mx-5p4w
    label: meissner@suse.de
tags:
  - nvd
epss: 0.00198
epssPercentile: 0.08828
ingestedAt: '2026-10-08T10:28:18.972Z'
---

## Overview

This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server.


In affected versions, NeuVector does not enforce TLS 
certificate verification when transmitting anonymous cluster data to the
 telemetry server. As a result, the communication channel is susceptible
 to man-in-the-middle (MITM) attacks, where an attacker could intercept 
or modify the transmitted data. Additionally, NeuVector loads the 
response of the telemetry server is loaded into memory without size 
limitation, which makes  it vulnerable to a Denial of Service(DoS) 
attack

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
