Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐹 Go

GHSA-8pxw-9c75-6w56

CRITICAL

GHSA-8pxw-9c75-6w56 is a critical-severity (CVSS 9.8) CWE-1393 vulnerability in github.com/neuvector/neuvector. O3 Security confirms whether GHSA-8pxw-9c75-6w56 is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.

NeuVector admin account has insecure default password

Also known asCVE-2025-8077GO-2025-3918
Published
Aug 28, 2025
Updated
Jul 2, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed

Blast Radius

1 pkg affected
🐹github.com/neuvector/neuvector

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Go packages — download data is not available via public APIs for these ecosystems.

Description

Impact

A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in admin account. If this password is not changed immediately after deployment, any workload with network access within the cluster could use the default credentials to obtain an authentication token. This token can then be used to perform any operation via NeuVector APIs.

In earlier versions, NeuVector supports setting the default (bootstrap) password for the admin account using a Kubernetes Secret named neuvector-bootstrap-secret. This Secret must contain a key named bootstrapPassword. However, if NeuVector fails to retrieve this value, it falls back to the fixed default password.

Patches

This issue is resolved in NeuVector version 5.4.6 and later. For rolling upgrades, it's strongly recommended to change the default admin password to a secure one.

Starting from version 5.4.6, NeuVector introduces additional Kubernetes RBAC permissions to ensure the bootstrap password can be securely managed via Secrets:

kubectl create role neuvector-binding-secret-controller \
  --verb=create,patch,update --resource=secrets -n {neuvector}

kubectl create rolebinding neuvector-binding-secret-controller \
  --role=neuvector-binding-secret-controller \
  --serviceaccount=neuvector:controller \
  --serviceaccount=neuvector:default -n {neuvector}
  • These RBAC roles are automatically applied when deploying via Helm.
  • If deploying or upgrading manually, you must create these roles before starting NeuVector.

NOTE: If these roles are not present, the NeuVector controller (from version 5.4.6 onward) does not start.

Behavior in Patched Versions

  • Upgrades: NeuVector does not reset any existing account passwords. It's strongly recommended to change the default admin password to a secure one.
  • New deployments:
    • If bootstrapPassword is not set in the `neuvector-bootstrap-secret, NeuVector generates a secure password and stores it in the same Secret.

On first login, the default admin must retrieve the password using:

kubectl get secret -n {neuvector} neuvector-bootstrap-secret \
  -o go-template='{{ .data.bootstrapPassword | base64decode }}{{ "\n" }}'

The password must be changed during the first login via the NeuVector UI.

NOTE: If the default admin password is set using a Kubernetes ConfigMap or a persistent backup (not a fixed string), this value takes precedence over the Secret-based mechanism.

Workarounds

For existing vulnerable versions, log in to the NeuVector UI immediately after deployment and update the default admin password.

References

If you have any questions or comments about this advisory:

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐹Gogithub.com/neuvector/neuvectorall versions0.0.0-20250825191744-da1a462074c3

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for github.com/neuvector/neuvector. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.

  2. Fix

    Update github.com/neuvector/neuvector to 0.0.0-20250825191744-da1a462074c3 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-8pxw-9c75-6w56 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 pinpoints whether GHSA-8pxw-9c75-6w56 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.

Tailored to GHSA-8pxw-9c75-6w56. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

### Impact A vulnerability exists in NeuVector versions up to and including **5.4.5**, where a fixed string is used as the default password for the built-in `admin` account. If this password is not changed immediately after deployment, any workload with network access within the cluster could use the default credentials to obtain an authentication token. This token can then be used to perform any operation via NeuVector APIs. In earlier versions, NeuVector supports setting the default (bootstrap) password for the `admin` account using a Kubernetes Secret named `neuvector-bootstrap-secret`. T
O3 Security · Impact-Aware SCA

Is GHSA-8pxw-9c75-6w56 in your dependencies?

O3 detects GHSA-8pxw-9c75-6w56 across Go dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.