and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it
to bypass TLS as a security control.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pgh9-mpwc-8jjf | Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS |
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suse
Suse harvester |
|
| Vendors & Products |
Suse
Suse harvester |
Tue, 16 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control. | |
| Title | Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-06-16T17:52:30.747Z
Reserved: 2026-03-03T12:54:04.008Z
Link: CVE-2025-71261
Updated: 2026-06-16T17:52:26.836Z
Status : Awaiting Analysis
Published: 2026-06-16T17:16:30.193
Modified: 2026-06-16T17:37:16.933
Link: CVE-2025-71261
No data.
OpenCVE Enrichment
Updated: 2026-06-17T21:45:02Z
Github GHSA