neuvector vulnerabilities
CVEs whose affected-version data names the neuvector package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-78428High· 8.0For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
▾ Twilightgo · neuvectorEPSS 0.24%via NVD
CVE-2026-78426Low· 3.7The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equ…
▾ Sunlitgo · neuvectorEPSS 0.12%via NVD