Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-78428 2 Go, Suse 2 Neuvector, Neuvector 2026-09-28 N/A
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
CVE-2026-78426 2 Go, Suse 2 Neuvector, Neuvector 2026-09-28 N/A
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.