{"schema_version":"1.9.0","id":"CVE-2025-54471","published":"2025-10-30T09:45:56.931Z","modified":"2026-08-12T15:14:03.498348Z","aliases":["GHSA-h773-7gf7-9m2x","GO-2025-4043"],"related":["CGA-26m7-7hp5-7gpg","openSUSE-SU-2025:15710-1","openSUSE-SU-2026:21483-1"],"summary":"NeuVector is shipping cryptographic material into its binary","details":"NeuVector used a hard-coded cryptographic key embedded in the source \ncode. At compilation time, the key value was replaced with the secret \nkey value and used to encrypt sensitive configurations  when NeuVector \nstores the data.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/neuvector/neuvector","events":[{"introduced":"eb1008e59c189eaebd96d51622df02e572c1a673"},{"fixed":"06424701e69bf1eb76ff90180d78853fded93021"}],"database_specific":{"extracted_events":[{"introduced":"5.3.0"},{"fixed":"5.4.7"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54471.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["262057388879917243189218491470984257527","14921899989987925630745045864773771899","39336313110153916292610461233912775615","122213556171299040661316363932857227343","248864694094604996174521579548084376617","245555888558265551945563786837230817483","241126453214753175649298278327804890624","123501170731759099835043262120301087313","307078153949658971802958921264443009462","280812318964051615609602534227852975830","51073143911989685228255760958889349844","322863322263352202393715665988828156123","333317758168122818203689769233219989536","145293007820601120448501876307783643629","205855968643439065789807805755472618390","71630680853029690589418460919674490123","69463341289600039050080627345162218089","191300362064051485058579562155928839556","211050457160173882409008987861322706250","251416315217988600183181041546450719320","8539180465425760721971263313424676338","176963135227364512382482193004657182656","79142855919862123745364460847322458251","23291377475150734789415874060058720199","193629810988016936904994233841817424087","136082482819317702170984834423328308783","170444029580348895673865957708906026185","151389820566683325416706412605668287280","265956433710846152281833282779939580439","246485831115555678983439992929954130719"],"threshold":0.9},"id":"CVE-2025-54471-4d8d5b72","signature_type":"Line","signature_version":"v1","source":"https://github.com/neuvector/neuvector/commit/06424701e69bf1eb76ff90180d78853fded93021","target":{"file":"monitor/monitor.c"}},{"deprecated":false,"digest":{"function_hash":"265690441905594406101508408213789672699","length":963},"id":"CVE-2025-54471-8127bb67","signature_type":"Function","signature_version":"v1","source":"https://github.com/neuvector/neuvector/commit/06424701e69bf1eb76ff90180d78853fded93021","target":{"file":"monitor/monitor.c","function":"check_consul_ports"}},{"deprecated":false,"digest":{"function_hash":"282408489853289947297947876889022519981","length":10755},"id":"CVE-2025-54471-e59796ed","signature_type":"Function","signature_version":"v1","source":"https://github.com/neuvector/neuvector/commit/06424701e69bf1eb76ff90180d78853fded93021","target":{"file":"monitor/monitor.c","function":"fork_exec"}}],"vanir_signatures_modified":"2026-08-12T15:14:03Z"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54471.json"},{"type":"ADVISORY","url":"https://github.com/neuvector/neuvector/security/advisories/GHSA-h773-7gf7-9m2x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54471"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-54471"}],"database_specific":{"cna_assigner":"suse","cwe_ids":["CWE-321"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54471.json","unresolved_ranges":[{"extracted_events":[{"introduced":"0.0.0-20230727023453-1c4957d53911"},{"fixed":"0.0.0-20251020133207-084a437033b4"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}