NeuVector 准入 Webhook 在策略评估时会静默排除那些镜像路径匹配其中三个硬编码服务网格 sidecar 镜像的容器。由于镜像路径完全由工作负载作者控制,任何能够部署工作负载的用户都只需将其镜像路径命名为这三个 sidecar 镜像之一,即可绕过准入拒绝规则。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| go | github.com/neuvector/neuvector | 0 ~ v5.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78428 | 8.0 HIGH | Flaw in Nuevector can result in one user receiving another user's authenticated session wh |
| CVE-2026-78425 | 7.6 HIGH | SAML Audience Confusion Allows Cross-SP Authentication |
| CVE-2026-78426 | 3.7 LOW | Logout bypass via alternate JWT spelling |
No comments yet