PT-2026-38260 · Suse+1 · Harvester+1

Published

2026-05-06

·

Updated

2026-06-16

·

CVE-2025-71261

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions SUSE Virtualization versions prior to 1.8.0
Description A security gap exists in the SUSE Virtualization Rancher integration mechanism where the registration client uses an insecure TLS option that fails to verify the remote server's certificate. An attacker with network-level access between SUSE Virtualization and Rancher Manager could interfere with the TLS handshake to bypass TLS security controls, potentially misleading the registration client into sending requests to an impersonated service via a man-in-the-middle attack. Furthermore, the system processes response payloads without size validation, which could allow an attacker to induce a memory buffer overflow, leading to a crash of the registration controller. This issue specifically affects the cluster-registration-url setting.
Recommendations Update to version 1.8.0 or newer. As a temporary workaround, ensure that only authorized cluster administrators can access and modify the cluster-registration-url setting.

Fix

DoS

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71261
GHSA-PGH9-MPWC-8JJF

Affected Products

Harvester
Github.Com/Harvester/Harvester