Medium severity5.3GHSA Advisory· Published Sep 17, 2025· Updated Apr 15, 2026
CVE-2025-53884
CVE-2025-53884
Description
NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of known passwords are precomputed).
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/neuvector/neuvectorGo | >= 5.0.0, < 5.4.6 | 5.4.6 |
github.com/neuvector/neuvectorGo | < 0.0.0-20250825191744-da1a462074c3 | 0.0.0-20250825191744-da1a462074c3 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.