StackRadar

CVE-2025-54467

Unscored

Advisory

Published 8 Sept 2025In the index since 6 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
16th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1
of 17,781 indexed, latest versions
Container images
3
deployed by those charts
Fix available
None
affected package

NeuVector process with sensitive arguments lead to leakage in github.com/neuvector/neuvector

Carried by container images the latest versions of 1 of 17,781 indexed charts deploy, on 3 images.

Affected packageAffected versionsFixed inImages
github.com/neuvector/neuvectorgolangv0.0.0-20260720233621-8b367c616b18, v0.0.0-20260807151606-c13b2f609e6c+dirtyno fix listed3
OSV records
GO-2025-3919
Also known as
GHSA-w54x-xfxg-4gxq

Charts affected

1 by stars
ChartLatestAffected imagesRadar Score
coreneuvectorchartsVerified publisher2.11.13 of 5See more

core neuvectorcharts 2.11.1

3 of the 5 container images this version deploys carry CVE-2025-54467.

Container imageDigestPackageFixed in
neuvector/controller:5.6.1ae45c394f1ac
github.com/neuvector/neuvector@v0.0.0-20260807151606-c13b2f609e6c+dirty
no fix listed
neuvector/enforcer:5.6.1aa2137cc90ec
github.com/neuvector/neuvector@v0.0.0-20260807151606-c13b2f609e6c+dirty
no fix listed
neuvector/scanner:6ac0167154880
github.com/neuvector/neuvector@v0.0.0-20260720233621-8b367c616b18
no fix listed

Open the chart page →

884

Container images carrying it

3 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
neuvector/controller:5.6.1ae45c394f1ac
github.com/neuvector/neuvector@v0.0.0-20260807151606-c13b2f609e6c+dirty
no fix listed
1
neuvector/enforcer:5.6.1aa2137cc90ec
github.com/neuvector/neuvector@v0.0.0-20260807151606-c13b2f609e6c+dirty
no fix listed
1
neuvector/scanner:6ac0167154880
github.com/neuvector/neuvector@v0.0.0-20260720233621-8b367c616b18
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.