5.x Release Notes
Release Notes for 5.xβ
To receive email notifications of new releases, please subscribe to this SUSE mailing list: https://lists.suse.com/mailman/listinfo/neuvector-updates
5.6.2 September 2026β
When upgrading controllers to version 5.6.2 (or later) from a version that does not support critical-level severity (e.g., 5.5.3`), existing scanner pods must be restarted or redeployed.
Older scanner pods cache the controller's initial capability response. They will not recognize that the upgraded controller supports critical-level severity until they are restarted and re-query the controller on startup.
Feature requestsβ
- NVSHAS-10317: [Web UI] Once CA is added, TLS CA file should not be editable
Enhancementβ
- issue-2668: Add Traefik details into the NV Helm Chart
Bug fixesβ
- NVSHAS-10289: Group contention resolution Restrict Mode on k3s/rke2 yields unexpected results
- NVSHAS-10331: HTTP chunk size exceeds the configured limit of 31457280 bytes when exporting Vulnerabilities
- issue-1272: "Vulnerabilities" column always shows wrong number in "Details" section
- issue-2673: size the AF_PACKET ring blocks from the runtime page size
- issue-2686: Duplicate response rules are created when importing(thru CRD) same-name response rules with changes
- issue-2709: When CRD-defined response rules are triggered, the webhook call(if configured) is not sent
- issue-2727: NV doesn't prevent user from importing federated groups/policies thru CRD
- fix: support automate module name with parsing cap
- chore(deps): dependency updates & golang upgrade
Referencesβ
- Admission Control Bypass via Hardcoded Sidecar Image Exemption
- Logout bypass via alternate JWT spelling
- The SAML and OpenID SSO login does not have proper identifier for login users
- SAML Audience Confusion Allows Cross-SP Authentication
- OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes
5.6.1 August 2026β
When upgrading controllers to version 5.6.1-rc1 (or later) from a version that does not support critical-level severity (e.g., 5.5.3), existing scanner pods must be restarted or redeployed.
Older scanner pods cache the controller's initial capability response. They will not recognize that the upgraded controller supports critical-level severity until they are restarted and re-query the controller on startup.
Feature requestsβ
- issue-2614: Revert "zero-drift" for Processes to NOT be the default.
- feat: Better error handling for image scan.
- feat: Provide vcs information in executible files.
Bug fixesβ
- issue-2669: Suppress log messages Benchmark report not found.
- fix: Match Istio proxymesh traffic against parent workload rules
- fix: Size the netlink dump buffer for kernels with pages over 4K
- fix: Fix null value shown in dashboard risk panel.
- fix: Resolve code scanning findings & reduce unnecessary info/warn logs.
5.6.0 July 2026β
When upgrading controllers to version 5.6.0-rc1 (or later) from a version that does not support critical-level severity (e.g., 5.5.3), existing scanner pods must be restarted or redeployed.
Older scanner pods cache the controller's initial capability response. They will not recognize that the upgraded controller supports critical-level severity until they are restarted and re-query the controller on startup.
Feature requestsβ
- issue-2235: Add a column containing the image digest in generated reports for containers.
- NVSHAS-8242: Add Critical CVE severity to support CVSS v3 scores from 9.0 to 10.0.
- NVSHAS-10298: Include the CVE database version in the NeuVector vulnerability report.
- feat: Move the readiness probe from
exectohttpGet. - NVSHAS-10024: Add an option to filter vulnerabilities based on the base OS image.
- issue-1195: Show the severity filter in the report filter.
- feat: Optimize the scanner registration flow.
Bug fixesβ
- NVSHAS-10283: Custom groups with image or namespace criteria show no members.
- issue-2348: Hide global permissions from the Show advanced settings table.
- issue-2355: The View all scanned images page in the registry does not show critical vulnerabilities.
- enhance: Reject loading or uploading an empty or corrupted CVE database.
- nvbench: The k3s CIS check OOM-kills the enforcer on nodes with a large journal.
- fix: Allow explicit network rules in restrictive group mode.
- fix(lint): Resolve
errcheckfindings. - fix(code-scanning): Resolve code scanning findings.
- issue-2519: silent error handling in consul kv slot reads in network functions
- issue-2485: scanner cvedb upgrade takes huge memory utilization
5.5.3 June 2026β
This release rebuilds the container images to patch CVEs in the underlying operating system, application, and library dependencies. It includes no new features or breaking changes and is fully backward compatible.
Bug fixesβ
- #2227: UBI controller images do not work in newer OpenShift environments.
5.5.2 May 2026β
This release rebuilds the container images to patch CVEs in the underlying operating system, application, and library dependencies. It includes no new features or breaking changes and is fully backward compatible.
5.5.1 April 2026β
Feature requestsβ
- #2248: Expose OS scan support status from scanner results
Bugs fixedβ
- #1140: The accept vulnerabilities in Node page can be brought out of the View drop down box like that of the container
- #1154: Report column content shifting with multiple fix versions separated by a comma
- #2255: Unable to scan image registry by API(v1/scan/repository) with proxy enabled through curl
- #1170: Event handling function that is set in the icon element does not work after Angular 20 migration.
- #1175: The federated prefix and the registry name are not properly aligned when attempting to add a federated registry to the primary cluster
- #1156: Auto-scan button malfunctioning
- #1179: Show advance setting button is not displayed when creating user
- #1183: Auto-scan toggle state is not synchronized between Dashboard and Assets -> Nodes page
5.5.0 March 2026β
Feature requestsβ
- NVSHAS-10131: Improve the Vulnerabilities Report
- NVSHAS-10195: Upgrade UI framework from Angular 14 to Angular 20
Bugs fixedβ
- NVSHAS-10244: NeuVector Rancher SSO authentication error when Rancher Helm release name is not
rancher - NVSHAS-10255: Add user validation on APIs that do not communicate with the controller
- NVSHAS-10264: Display control is missing on the API key page
- NVSHAS-10281: Suppress log in the response rule is not working
=== Announcement
- NVSHAS-10246: Deprecate Docker native support in NeuVector
=== References
5.4.9 February 2026β
New Featuresβ
- NVSHAS-9921: Managed cluster deployed via configmap and without persistent storage should be able to reconnect after a disconnect
- NVSHAS-10014: NeuVector needs option to enable GPU acceleration before opening "Network Activity"
Bugs Fixedβ
- NVSHAS-9936: [RST-Documentation] Need to update documentation for embargoed issue
- NVSHAS-10036: Rancher to NV login is not working for some users
- NVSHAS-10061: Remote Repository scan reporting "RPC request fail"
- NVSHAS-10121: [UI-ext] Dashboard information missing in Rancher UI Extension
- NVSHAS-10175: Refactor the OPA generate function to avoid rego online verify
- NVSHAS-10203: [Dup][UI-ext] Dashboard information missing in Rancher UI Extension
- NVSHAS-10207: Country flag is not showing on the product build
- NVSHAS-10209: [Registry adapter] Registry value is missing a slash afterwards in the scan-report
- NVSHAS-10213: [Scanner] Handling of passwords as command arguments (20)
- NVSHAS-10214: [Controller] InstallationID is used for encrypt/decrypt user token (24)
- NVSHAS-10215: The review rule button is not visible in the managed cluster
- NVSHAS-10218: [Controller] Lack of validation for RSA Keysize (23)
- NVSHAS-10219: [Controller] InstallationID is used for encrypt/decrypt user token (24)
- NVSHAS-10221: [Controller] Export local groups(and other policies) thru redirected UI from primary cluster always fails
- NVSHAS-10222: [Manager] After a cluster successfully joins fed, UI doesn't auto-refresh
- NVSHAS-10247: Disable the access to subpath for some manager APIs
5.4.8 December 2025β
New Featuresβ
- NVSHAS-10186: Return file_path after export to remote repository successfully
- NVSHAS-10168: Add remote export option to system configurations page - Federation only
- NVSHAS-10142: Make 'enforce TLS verification' enabled by default for new NV deployment (6)
- NVSHAS-10068: [UI] Support "Export"/"Import" buttons on all fed-related policy pages
- NVSHAS-10026: Possibility of creating Federation rules through automation RESTAPI only
- NVSHAS-9300: Helm chart: manager-service and controller-service customizable TCP ports
Bugs Fixedβ
- NVSHAS-10196: Replace country flag images to avoid CVE-2025-66412 / GHSA-v4hv-rgfq-gp49
- NVSHAS-10185: Suggest add "Fed" in exported file name when exporting fed policy to local or remote in NV UI
- NVSHAS-10180: [C03084][C03092][C03085] [Container Scan] It fails to detect package.json related modules
- NVSHAS-10174: Controller wrongly allows 'Committer Name' & 'Email' in Remote Repository Configuration to be empty in POST request
- NVSHAS-10173: [UI] Newly-created rule in fed DLP/WAF sensor page cannot be edited
- NVSHAS-10172: [UI] Incorrect floating message when try to delete a fed webhook that is in-use
- NVSHAS-10171: [UI] strange behavior for Federated Policy -> Configuration page
- NVSHAS-10169: [Federated policy][Configuration] After webhook is updated, the reflected record shows the type is user created
- NVSHAS-10167: [UI] Incorrect response rules displayed after selecting a fed group
- NVSHAS-10166: [UI] Incorrect floating message after importing fed configuration
- NVSHAS-10165: [UI] Network policy mode and Process profile mode should not be in the export federated groups modal
- NVSHAS-10164: [Groups] Hide selection checkbox on federated groups on local group page
- NVSHAS-10163: [UI] 'Export to Remote Repository' is missing for all fed policy pages' export
- NVSHAS-10162: HIGH CVEs FOUND in NV Images
- NVSHAS-10157: [Scan] Fixed Version is empty in some image
- NVSHAS-10156: NeuVector Scanner is not reporting CVEs for the npm repository tinymce
- NVSHAS-10154: Only response rules without group can be exported in response rules page
- NVSHAS-10151: Incorrect payload for creating fed WAF sensor
- NVSHAS-10140: Unexpected checkbox for DLP/WAF export
- NVSHAS-10139: [Controller] Controller does not initialize when enforcer is not deployed
- NVSHAS-10133: Enforcer pods crashing
- NVSHAS-10128: [Controller] Controller doesnt initialize when disabling scanner using cve.scanner.enabled=false parameter
- NVSHAS-10116: Controller throwing errors "...Watch failure - error..."
- NVSHAS-10113: [UI] 'View Federated Repositories' on Assets -> Registries page
References:β
5.4.7 October 2025β
In NeuVector v5.4.6 and later, the Compliance feature requires NeuVector Prime and must have controller.prime.enabled: true set in the values.yaml file. If the Compliance feature is missing after upgrade, refer toCompliance Feature Behavior Across NeuVector Versions.
New Featuresβ
- NVSHAS-10085: Add a configuration setting on UI for allowing groups switch between least privileged & more privileged.
- NVSHAS-10084: Move admission control related crd structs in
nvsecurityrule_def.gofromresource/toapi/for dependency issue when buildingneuvector-kubewarden-policy-converter. - NVSHAS-10073: Add a new field for exported admission control rules in the yaml file.
- NVSHAS-10067: Cli for new configuration setting that allows ns user to export.
- NVSHAS-10065: Add a configuration setting on UI for allowing namespace user to export.
- NVSHAS-9918 : Add ability to control policy restriction mode.
Bugs Fixedβ
- NVSHAS-10080: Cannot create a federal response rule for Admission event
- NVSHAS-10077: Unexpected checkbox for admission control export
- NVSHAS-10071: process rule missing in enforcer pod
- NVSHAS-10070: Creating multiple response rule fail on some cluster
- NVSHAS-10066: First time login does not show link for bootstrap helper when user directly access UI in Rancher deployment
- NVSHAS-10054: Do not always reset k8s ValidatingWebhookConfiguration to avoid infinite updating loops
- NVSHAS-10049: Follow up on the NV scan JFrog Subdomain mode issue
- NVSHAS-10006: Group export is empty for namespace users.
- NVSHAS-9761 : Harbor registry with s3 storage backend repository scan error
References:β
- Removal of hard-coded encryption key
- Enforce TLS verification for requests to Telemetry server
- Check consul ports for enforcer
Refer to the Security Advisory and CVEs documentation for more information.
5.4.6 August 2025β
In NeuVector v5.4.6 and later, the Compliance feature requires NeuVector Prime and must have controller.prime.enabled: true set in the values.yaml file. If the Compliance feature is missing after upgrade, refer toCompliance Feature Behavior Across NeuVector Versions.
New Featuresβ
- NVSHAS-6733: Export response rules as CRD.
- NVSHAS-9899: NeuVector Process Profile Alerts for Java Services contain sensitive data.
- NVSHAS-9990: Adopt new hash algorithm for user passwords.
- NVSHAS-9968: Support setting default admin account's default password.
Bugs Fixedβ
- NVSHAS-10062: Manager not showing ERROR when failing to create admin password during 1st login.
- NVSHAS-10041: Federation operation failed "invalid data" when configuring federation through ConfigMap.
- NVSHAS-10018: Neuvector is not scanning all images in GitLab Registry.
- NVSHAS-10017: False Positive Security Alert related to allowed process.
- NVSHAS-10001: Protect/Monitor enforcements "linger" after group deletion.
- NVSHAS-9985: NeuVector (Fed Master) creates a problem for all requests coming from outside.
- NVSHAS-9981: Security Event is triggered whenever a new "Process Profile Rule" is added or changed in a group.
Security Advisoriesβ
- Admin account has insecure default password
- Insecure password management vulnerable to rainbow attacks
- Process with sensitive arguments lead to leakage
5.4.5 July 2025β
New Featuresβ
- NVSHAS-9776: Add etcd toleration in helm chart.
Bug Fixesβ
- NVSHAS-9507: OCI container not getting scanned.
- NVSHAS-9787: Remove unnecessary manager log.
- NVSHAS-9788: Refine algorithm for generating certificate.
- NVSHAS-9789: Remove unnecessary manager log on remote registry configuration.
- NVSHAS-9867: NeuVector shows
.NET Library System.Formats.Asn1 v8.013affected CVE 2024-38095. - NVSHAS-9883: [quay.io]Wildcard filters not working for docker registry.
- NVSHAS-9911: Scanning the repo using REST API results in an incorrect "message"
- NVSHAS-9930: CVE-2018-20796 for
glibc/libc-bin : 2.36-9+deb12u10- False positive. - NVSHAS-9933: Registry-adapter feature (Harbor) showing errors in target registry while scanning.
- NVSHAS-9934: Suspected zero-drift functionality malfunction.
- NVSHAS-9940: NV scan JFrog Subdomain mode issue.
- NVSHAS-9942: Images scans for customer images are failing.
- NVSHAS-9945: When the process name is too long, it's difficult to determine how to create the appropriate process profile rule.
- NVSHAS-9946: Display issue with Admission Control alert for Credential Type.
- NVSHAS-9947: [UI-ext] Compliance Chart Missing "Manual" Status in Rancher NeuVector.
- NVSHAS-9948: After upgrading to
5.4.3NeuVector configuration has been lost. - NVSHAS-9949: [Harbor][Incorrect user/pw] It still scan images even inputting incorrect user/pw.
- NVSHAS-9952: Remove 'signature' from usage report because NV no longer issues/checks the license key.
- NVSHAS-9953: Pods Enforcer keeps restarting.
- NVSHAS-9954: NeuVector prometheus-exporter generating duplicated metrics.
- NVSHAS-9958: Network rule enforcement takes long time.
- NVSHAS-9960: Scanners not working.
- NVSHAS-9969: fatal error: concurrent map writes results in enforcer component restart.
- NVSHAS-9971: NV UI about
Get Bootstrap Password. - NVSHAS-9975: [Manager] TypeError:
this.mousemoveListeneris not a function is observed on the NV GUI. - NVSHAS-9986: Process profile rules and File access rules cannot be edited and removed in Federated policy group view.
- NVSHAS-9988: UI: Group pages is not showing all groups when more than 2k groups present.
- NVSHAS-9991: The group
nv.gatekeeper-controller-manager.openshift-azure-guardrailsis missing from UI. - NVSHAS-9993: Replace md5 by sha256.
- NVSHAS-9994: The enforcer pod keeps restarting.
- NVSHAS-9996: NeuVector Helm chart should allow non-privileged mode of enforcer pods.
- NVSHAS-9998: Cannot export group from Neuvector federated master.
- NVSHAS-10000: Upgrade NV to BCI 15.7.
- NVSHAS-10003: Reload page does not work on standalone NV page while a Rancher UI is opening.
- NVSHAS-10008: Registry Scan - View menu is broken for Scanned Image.
- NVSHAS-10010: TCP SYN Flood blocks ingress causing complete ingress traffic being blocked.
5.4.4 May 2025β
New Featuresβ
- NVSHAS-9915: Show scan results from the Harbor scanner module in the NeuVector UI.
- NVSHAS-9904: Expose
imagePullPolicytovalues.yamlfor each component. - NVSHAS-9869: UI: Move DDoS Controls to the Group Pane.
- NVSHAS-9840: [GCP] NeuVector Autopilot support for GCP.
- NVSHAS-9248: Display unused Process/Network Rules with counters and
Last Usedtimestamp. - NVSHAS-8160: [Controller] Adjust some items for Security Risk Score calculation.
- NVSHAS-4673: Suggestion to add message before exporting groups.
Bug Fixesβ
- NVSHAS-9931: Add a warning if there are inconsistent versions of NeuVector products in multi-cluster.
- NVSHAS-9925:
/v1/scan/asset/imagesAPI on the Registry Page fails. - NVSHAS-9913: Problem with deleting several Network Rules related to Workload:XYZ groups.
- NVSHAS-9912: Update Helm about some K8s RBAC permissions needed by the controller service account.
- NVSHAS-9909: "Signed Out - Go to loading page" message displayed when using NeuVector Rancher NavLink.
- NVSHAS-9898: In a federated environment, modifying the criteria of a customer-created fed.* group (e.g. fed.core-systems) doesn't work.
- NVSHAS-9894: [Enforcer]
Nv.protectdenies controller readiness probe commandcat /tmp/ready. - NVSHAS-9886: Network activity does not resolve domain names for the custom external group connections.
- NVSHAS-9884: [Node Scan][Container Scan] Scan will fail.
- NVSHAS-9873: UI Advanced Filter search issue in NeuVector 5.4.2.
- NVSHAS-9865: Exported network policies differ, depending on the order of selection (same groups selected).
- NVSHAS-9828: [Enforcer: process] The NeuVector Enforcer is not able to detect short lived pods (Anything less than 5 seconds).
- NVSHAS-9783: After adding the network policy to deny icmp packets, NeuVector does not see any alerts in
Security Events. - NVSHAS-9176: Show a script error in the Security Risks > Vulnerabilities page if a user permission with the namespace
rt_scan:wrole is logged in.
5.4.3 March 2025β
New Featuresβ
- NVSHAS-9793: Allow Fed Global roles in LDAP/userinitcfg when deploying NeuVector through the ConfigMap and Secret.
- NVSHAS-9764: [RFE] Add support for Azure for "Remote Repository Configuration".
- NVSHAS-9759: Add date details in the Ingress-Exposure Report.
- NVSHAS-9755: Request to display environment variable names alongside values in alerts for secrets.
- NVSHAS-9748: [Helm] NeuVector Helm update for supporting name referral for common groups in CRD (NVSHAS0-4717).
- NVSHAS-9426: Add hostPath for Scanner to Helm chart.
- NVSHAS-9326: NeuVector - Harbor Pluggable Scanner Module.
- NVSHAS-9835: UI for disable auto-scan for node.
- NVSHAS-7997: Scanner connector for ghcr.io.
- NVSHAS-7982: Assign WAF sensors from Federation Master.
Bug Fixesβ
- NVSHAS-9849: Enforcers not registering with controllers.
- NVSHAS-9847: Wildcard filters not working for Docker registry.
- NVSHAS-9833: Configuration restore fails in Rancher deployments.
- NVSHAS-9832: Problem with creating network rules using the Workload group.
- NVSHAS-9821: Process name is not matched from the command line for the Process Profit Rule Alert.
- NVSHAS-9817: Creating NvClusterSecurityRule CRD shows successful creation, but it was not actually created due to duplicated process rule entries.
- NVSHAS-9812: NeuVector prometheus-exporter wrong metrics.
- NVSHAS-9811: [Manager] Unable to access GUI when using a custom certificate (CA) with root CA and intermediate CA on the secret.
- NVSHAS-9801: FIPS mode +
manager.env.ssl=falsecauses Manager to error out. - NVSHAS-9792: Federation policy syncing failing due to body size exceeding Consul max.
- NVSHAS-9784: NeuVector returning 404 during Jfrog image repository scanning.
- NVSHAS-9783: After adding the network policy to deny icmp packets the user does not see any alert in "Security Events".
- NVSHAS-9780: NeuVector single sign on not working with Rancher NavLink.
- NVSHAS-9777: Webhook JSON with duplicated "level" keys.
- NVSHAS-9770: Auto-Switch after Zero-Drift mode switches incorrect policy.
- NVSHAS-9765: File access doesn't get fully blocked in Protect mode.
- NVSHAS-9756: Enforcer reached maximum CPU and has several Memory Pressure alerts.
- NVSHAS-9668: Compliance test failing on RKE2.
- NVSHAS-9265: Incomplete and incorrect vulnerability scan results on PRE PCI environment.
- NVSHAS-9227: Registry scan gets stuck in the middle of scanning process and goes to "Idle" state.
- NVSHAS-9729: Incorrect count of vulnerabilities are observed when multiple statefulset with the "same name" in namespaces are deployed in a project.
- NVSHAS-9810: NeuVector controller not responding and UI not accessible.
5.4.2 January 2025β
New Featuresβ
- NVSHAS-9726: The monitor now passes proxy URL.
- NVSHAS-9719: Announces the retirement of built-in certificates.
- NVSHAS-9715: Helm Chart value support for setting nodeport on controller and manager.
- NVSHAS-9710: Include a sortable
feed_ratingcolumn into the Vulnerabilities tab. - NVSHAS-9669: Overall security score through REST API.
- NVSHAS-9590: Ability to choose which vulnerability score for all assets.
- NVSHAS-7555: Include "Auto Refresh" option under Security Events.
Bug Fixesβ
- NVSHAS-9662: Inconsistent Role/RoleBinding logic in Helm chart 2.8.2.
- NVSHAS-9652: Observed difference in syslog format in splunk.
- NVSHAS-9649: Container link produces 404 response code in security-event.
- NVSHAS-9613: NeuVector Manager Pod Error / NeuVector Web UI Unavailable.
- NVSHAS-9507: OCI container not getting scanned.
- NVSHAS-9443: Upgrade/Install through ArgoCD fails as it cannot create leases.coordination.k8s.io object.
- NVSHAS-9436: Possible CVE false negative against CVE-2024-7347.
- NVSHAS-8386: Private keys and self-signed certs still shipped in multiple images.
- NVSHAS-9754: [UI] Prevent Rancher relates SSO user disable Authentication of OpenShift or Rancher's RBAC.
- NVSHAS-9751: [Runtime Protection] Monitor Mode + Zero-Drift is not generating any alerts when a child process is executed.
- NVSHAS-9721: UI should pop up appropriate error message when user inputs wrong registry name.
- NVSHAS-9696: Inconsistent colour indication of assets on vulnerability page.
- NVSHAS-9686: Hardcoded namespace for the registry adapter certificate in the Neuvector Helm chart.
- NVSHAS-9678: Excessive error traces after the linter changes.
- NVSHAS-9670: Manager: Plain text response double quotes issue and java unnamed library issue in sbt run.
- NVSHAS-9667: Setting
CTRL_PATH_DEBUGenv variable to error in controller deployment is not working. - NVSHAS-9665: File Access rule: Delete predefined rules produces "setRowData" error.
- NVSHAS-9664: Policy Group: Delete custom script produces "setRowData" TypeError.
The default types of manager and registry adapter service have been changed to ClusterIP. Users are still able to override the setting by overridding the manager.svc.type and cve.adapter.svc.type if NodePort is preferred.
In the NeuVector 5.4.2 release, support is discontinued for deployments using the built-in internal certificate. The certificate found at /etc/neuvector/certs/internal within NeuVector 5.4.2 container images will be removed. To continue using NeuVector, users should:
5.4.2 New Installation:β
Using Helm:β
- Enable the
internal.autoGenerateCertandinternal.autoRotateCertflags in the Helm charts (these will be enabled by default starting with the 5.4.2 release). Alternatively, a YAML method is linked below.
Using YAML:β
- Provide an internal certificate using the existing methods: https://open-docs.neuvector.com/deploying/production/internal
Upgrading from Previous Versions to 5.4.2:β
Please create and configure internal certificates from the scanner for the controller, enforcer, and registry-adapter to achieve a rolling update without losing data. It is still recommended to take a backup of your configuration before upgrading.
The following steps are only needed if your deployment uses a .yaml file. Upgrading using Helm does not need these additional steps due to the internal certificates getting created by default via the following flags: internal.autoGenerateCert and internal.autoRotateCert.
docker run -it --entrypoint=bash neuvector/scanner:3.654 -c "cat /etc/neuvector/certs/internal/ca.cert" > ca.crt
docker run -it --entrypoint=bash neuvector/scanner:3.654 -c "cat /etc/neuvector/certs/internal/cert.pem" > tls.crt
docker run -it --entrypoint=bash neuvector/scanner:3.654 -c "cat /etc/neuvector/certs/internal/cert.key" > tls.key
kubectl create secret generic internal-cert -n neuvector --from-file=tls.key --from-file=tls.crt --from-file=ca.crt
Sample 5.4.2 yaml with internal certificate configured: https://github.com/neuvector/manifests/blob/main/kubernetes/5.4.0/neuvector-k8s.yaml
Additional information about internal certificates.
In the case of a PVC configuration, users can configure an existing PVC in the new installation to restore a configuration.
Additional Note for Scanner:
For current users with versions prior to 5.4.2, the certificate will remain available in the neuvector/scanner:latest until March 31, 2025. After this date, it will be removed. Users should plan to provide the same internal certificate to the controller, enforcer, scanner, and registry adapter to continue using the scanner.
Please note the stand-alone scanner will not be affected by these changes.
5.4.1 November 2024β
New Featuresβ
- NVSHAS-8583: Setting granular policy modes for rule sets, separate network policy mode and profile mode at per group level.
- NVSHAS-9440: Support separate network mode and Process and File mode in CRD.
- NVSHAS-9369: Add debug log category via helm deployment support for controller.
- NVSHAS-9040: Improve syslog message when admission control rule is denied in monitor mode.
Bug Fixesβ
- NVSHAS-9416: [Scanner] activemq-all-5.8.0.redhat-60024.jar can NOT be detected with any vul (but previous scanner build can).
- NVSHAS-9447: Controller/Scanner pods crashing - "Unsupported system Exit".
- NVSHAS-9278: CVE-2024-41110 is found in the latest scanner image.
- NVSHAS-9467: Custom group defined by the pod label does not propagate its profile data on the children containers.
- NVSHAS-9442: Deployment issue on ArgoCD.
- NVSHAS-9436: Possible CVE false negative against CVE-2024-7347.
- NVSHAS-9468: Fix CVE-2020-26160 to replace jwt-go with jwt:v5.
- NVSHAS-9517: Admission control is not consistent, getting incorrect results.
- NVSHAS-9532: The image scan is completed but deployment is still not allowed.
- NVSHAS-9558: JWT token expire reports http.StatusRequestTimeout 408.
- NVSHAS-9576: Clear password field for registry data when user uses controller mode with Jenkins to scan.
- NVSHAS-9425: Create nfq when container has vxlan.
- NVSHAS-9571: [Registries] Filter for all scanned image does not work well.
- NVSHAS-9589: Managed clusters disconnected - Version mismatch with primary cluster.
- NVSHAS-8824: User fails to delete own groups, cannot create namespace-scoped groups.
- NVSHAS-9605: Export group with invalid policy mode & process profile mode values is mistakenly allowed.
- NVSHAS-9608: Scanner does not report any error when controller reports an error for huge scan results ~23MB.
- NVSHAS-9534: Display error in admission controls.
- NVSHAS-9600: Cannot disable controller debug.
- NVSHAS-9631: Reduce some enforcer errors.
- NVSHAS-9645: Pre-existing CRD processing fails.
- NVSHAS-9592: No new scan despite new DB version.
- NVSHAS-9212: Display alerting msg in GET(/v1/eula) if the neuvector-binding-secret role(binding) is incorrect.
- NVSHAS-9367: Enhance error messages when registry fails to be connected.
- NVSHAS-9475: Background grid print is not fully covering when menu is collapsed.
- NVSHAS-9485: Incorrect message for 'Network Security Policy Mode' in UI.
- NVSHAS-9480: NV UI deployed on Rancher downstream cluster throws HTTP/403 after Rancher logout.
- NVSHAS-9547: Sorting is broken on the security risks --> vulnerabilities table.
- NVSHAS-9570: [Vulnerabilities] Change the legend description for different statuses on assets.
- NVSHAS-9561: Dashboard board overall security score should match the actual score.
- NVSHAS-9572: [Vulnerabilities] Filtered data was kept no matter user refresh or re-login on page.
- NVSHAS-9597: UI doesn't respond to any error when the controller returns 403 for POST(v1/group).
- NVSHAS-8682: CRD webhook service needs to be moved from crd helm chart to application helm chart.
Known issuesβ
- In the 2.8.3 chart release, we have moved a previously misallocated resource from crds to core. If you use both crds and core charts, you might see issues during upgrade if you deploy core first. To resolve this, upgrade the crds first and then core charts.
5.4 September 2024β
Overviewβ
- UI Improvements:
- Display Rancher SSO users.
- Manage JWT tokens.
- Enhanced image navigation, and scan result links.
- Security Enhancements:
- New compliance filters.
- Support for CIS benchmarks, and OCI image signing.
- Network & Monitoring:
- Advanced bandwidth and session tracking.
- DDoS monitoring.
- Multus network support.
- Cert Management:
- New notifications for expiring internal certificates, including rotation capabilities.
- Automation & Integration:
- Federation automation.
- Rancher RBAC integration.
- Improved admission control.
- Performance & Efficiency:
- Reduced memory usage.
- ISP data charge reduction.
- Scanner cache stats exposure.
- Usability Improvements:
- Bootstrap password support.
- Cloud billing data archiving.
- Namespace boundary enforcement.
New Featuresβ
- NVSHAS-9012: Displaying Rancher SSO users on NV UI that have the same user name.
- NVSHAS-8939: Provide an option on NV UI so that Rancher SSO session users can drop the current JWT token (i.e. logout).
- NVSHAS-7522: Easy image navigation through registries.
- NVSHAS-8148: Link from container image to registry image scan results.
- NVSHAS-9258: Add a new notification for expiring certificates and internal certs.
- NVSHAS-8915: Support for new compliance filters and Compliance report.
- NVSHAS-9403: Filemonitor-UI: Allow user to delete predefined file monitor rule.
- NVSHAS-8423: Detect group-level bandwidth, active session count, and session-rate violation based on configured thresholds.
- NVSHAS-9218: Support for federal and CRD groups for DDoS monitoring.
- NVSHAS-8461: Support CIS benchmarks for managed k8s services in the cloud.
- NVSHAS-7664: Reduce ISP data charges during registry scanning.
- NVSHAS-8868: Expose scanner cache statistics.
- NVSHAS-8676: NV Protect improvement for benchmark scripts.
- NVSHAS-9255: Customize Admission control search registries for image names without FQDN.
- NVSHAS-9144: ID added for vulnerability profile for easy identification.
- NVSHAS-7687: Support configuring log level (debug/error/info/warn) for enforcer and controller from CLI.
- NVSHAS-7518: Change internal certificates for NeuVector components.
- NVSHAS-9287: Enable internal cert rotation.
- NVSHAS-8562: Add internal cert expiration notification.
- NVSHAS-8486: Support Multus network interface.
- NVSHAS-7447: Rancher RBAC integration with NeuVector.
- NVSHAS-7822: Federation automation without scripting API calls.
- NVSHAS-8799: Create a Compliance Framework for importing Compliance Templates.
- NVSHAS-8773: Bootstrap password support during initial deployment.
- NVSHAS-6740: Improvement of zero-drift baseline profile by enforcing the learned list in protect mode.
- NVSHAS-8325: Enforce container namespace boundary for network rule.
- NVSHAS-8723: Archive cloud billing data.
- NVSHAS-9086: Reduce controller process memory usage by eliminating vulTrait data structure.
- NVSHAS-6979: Ability to include comment of response rule in alert content.
- NVSHAS-8845: Create APIKEY with role FedReader and FedAdmin.
- NVSHAS-9306: Admission Control configuration assessment shows rule ID responsible for allowed or denied deployments.
- NVSHAS-9078: Support for image signing for OCI images.
- NVSHAS-7945: (Available when deployed from a Rancher Chart.) Support DISA STIG benchmark for Kubernetes.
- NVSHAS-8234: Admission Control Logic allowing images that should be denied.
Bug Fixesβ
- NVSHAS-9005: TypeError in registries: Cannot read properties of undefined (reading 'total_records').
- NVSHAS-9085: Assets View PDF report shows 0% vulnerability even with present vulnerabilities.
- NVSHAS-9084: Assets View PDF report shows NaN when image list is empty.
- NVSHAS-9128: Security Events: Container cannot be displayed if there is no workload's namespace value.
- NVSHAS-9025: Neuvector vulnerability acceptance scope for containers.
- NVSHAS-9155: Registry Scan Image incorrect column name and missing File Name
- NVSHAS-9122: Neuvector master logs out any time when using "Multiple Cluster" with Rancher SSO login.
- NVSHAS-9266: Registry scan: Scan Report by Layer button should be hidden or disabled when there's no vulnerability.
- NVSHAS-9219: Allow users to enable server cert validation for auth servers.
- NVSHAS-9246: Filtering for CSV/PDF export does not work.
- NVSHAS-8947: Cannot import NV configuration when authenticated through Rancher SSO.
- NVSHAS-9282: UI: Editing OpenShift registry entry fails due to a missing token.
- NVSHAS-9098: Enhance risk page loading user experience.
- NVSHAS-9267: Do not allow UI on 5.4 master cluster to switch to pre-5.4 managed clusters because of REST API changes.
- NVSHAS-9285: UI: Dropdown list button overlaps with other elements.
- NVSHAS-9302: Cannot create APIKEY with role FedReader and FedAdmin.
- NVSHAS-8539: Reconfigure proxy setting loses password.
- NVSHAS-9293: Removal of unrelated image details in the vulnerability reports.
- NVSHAS-9238: UI doesn't refresh the displayed cluster name after it's changed.
- NVSHAS-9363: Notification Configuration > Webhooks grid are not properly aligned.
- NVSHAS-9362: Security Risk Vulnerabilities filter returns 0 results.
- NVSHAS-8699: Unable to distinguish the user if Rancher AD user is the same.
- NVSHAS-9062: Displaying Rancher SSO users on NV UI that have the same username (Conversion on controller).
- NVSHAS-9071: Some modules are not reported in the container scan only.
- NVSHAS-8242: gRPC call to test if controller handles critical severity.
- NVSHAS-8908: Parse X-Forwarded-Port correctly considering comma separator.
- NVSHAS-9024: AdmissionControl Risky Role Perf.
- NVSHAS-9091: Unable to report all modules under ol:9.1, photon:5.0, rhel:9.1, and amzn:2023 source in repo, registry, and standalone scan.
- NVSHAS-8997: Largely reduce per node policy slot number to improve performance.
- NVSHAS-9059: CRD groups visible in NV even after deletion from K8s.
- NVSHAS-9107: Goroutine crash at rest.handlerConfigLocalCluster.
- NVSHAS-9108: Port 18500 shouldn't be open.
- NVSHAS-9119: Goroutine crash at probe.(*FileNotificationCtr).AddContainer().
- NVSHAS-9125: CRD entry with invalid settings should not be allowed to create.
- NVSHAS-9124: Docker: many unexpected healthcheck process incidents are reported.
- NVSHAS-9111: NV should check
--event-qps > 0. - NVSHAS-9130: Unexpected Container.Package.Updated incidents are found after a specific container is started.
- NVSHAS-9080: Fed reader user is unable to access some REST APIs.
- NVSHAS-9092: Namespaced user should not see global assets.
- NVSHAS-9116: The worker cluster is able to leave if the connection is dropped.
- NVSHAS-8980: Get host and tunnel interface on node successfully in oc 4.15.
- NVSHAS-9188: Set mgmt-br interface as host interface for harvester node.
- NVSHAS-4858: Not expand containers group in controller to improve policy deployment performance and reduce CPU and memory usage.
- NVSHAS-8700: Rancher AD user is unable to log in to NeuVector sometimes.
- NVSHAS-9121: Group's Network Monitoring Threshold setting cannot be edited.
- NVSHAS-9189: Scan will get stuck in scheduling after controller is shutdown and restarted.
- NVSHAS-9019: Fix unsynchronized link state for host interface.
- NVSHAS-8305: Remove built-in certificate.
- NVSHAS-9013: Removing BPF filter on the process monitor.
- NVSHAS-7853: TLS handshake EOF.
- NVSHAS-9290: User-added process profile rule not taking effect with ZD enabled.
- NVSHAS-9301: NV deployed on Rancher Prime cannot tell it's Rancher flavor.
- NVSHAS-9289: Allow upgrade when RBAC is missing.
- NVSHAS-7601: Improve restore from PV config backup during scenarios.
- NVSHAS-7687: Add syslog level setting for enforcer.
- NVSHAS-9292: Fix Ingress Egress exposure shows 0 Vulnerabilities.
- NVSHAS-9270: Support k3s for CIS benchmark pipeline.
- NVSHAS-9338: Alert 'Managed cluster [id] is disconnected from primary'.
- NVSHAS-9358: Image scan using proxy would fail.
- NVSHAS-9337: Send log message when SYN flood is detected.
- NVSHAS-9209: Delete domain cache when namespace is deleted from k8s.
- NVSHAS-8985: Federated registries disappear after controller restart.
Known Issue:β
- NVSHAS-9443: Upgrade/Install through ArgoCD fails as it cannot create leases.coordination.k8s.io object.
- Workaround: Create the given lease objects before upgrading to 5.4.0 using ARGO CD. Change the namespace if it is different than neuvector.
cat <<EOF | kubectl apply -f -
apiVersion: coordination.k8s.io/v1
kind: Lease
metadata:
name: neuvector-controller
namespace: neuvector
spec:
leaseTransitions: 0
---
apiVersion: coordination.k8s.io/v1
kind: Lease
metadata:
name: neuvector-cert-upgrader
namespace: neuvector
spec:
leaseTransitions: 0
EOF
5.3.5 October 2025β
What's Changed
References of fixed CVEs:β
The fixed CVEs are:
- Telemetry sender is vulnerable to MITM and DoS
- Enforcer is vulnerable to Command Injection and Buffer overflow
For more information, refer to Security Advisories and CVEs
5.3.4 July 2024β
Bug Fixesβ
-
The
hostandtunnelinterface are successfully retrieved with OpenShift CLI v4.15. -
The IP range 169.254.x.x is excluded from the host interface IPs.
-
Reexam host interface after 1 minute of enforcer startup.
-
Fixed an issue where the OpenID issuer URL regex was failing.
-
Remediates following CVEs:
| CVE | Applies to | Impact |
|---|---|---|
| CVE-2023-42364 | busybox | π‘ Medium |
| CVE-2023-42365 | busybox | π‘ Medium |
| CVE-2024-6197 | curl | π‘ Medium |
| CVE-2024-6874 | curl | π‘ Medium |
| CVE-2024-5535 | openssl | π΄ Critical |
| CVE-2024-4741 | openssl | π‘ Medium |
5.2.4-s5 July 2024β
- Remediates following CVEs:
| CVE | Applies to | Impact |
|---|---|---|
| CVE-2023-42363 | busybox | π‘ Medium |
| CVE-2023-42364 | busybox | π‘ Medium |
| CVE-2023-42365 | busybox | π‘ Medium |
| CVE-2023-42366 | busybox | π‘ Medium |
| CVE-2024-6197 | curl | π‘ Medium |
| CVE-2024-6874 | curl | π‘ Medium |
| CVE-2024-5535 | openssl | π΄ Critical |
| CVE-2024-4603 | openssl | π‘ Medium |
| CVE-2024-4741 | openssl | π‘ Medium |
5.3.3 June 2024β
Enhancementsβ
- Allow users to block the usage of specific storage classes from the
Admission Controlspage. - The
LDAP Authenticationhas separated fields forbaseDNandgroupDNconfiguration. - The
Egress and Ingress charthas a new vulnerability column which contains theHighandMediumvulnerability count for each service.
Bug Fixesβ
- Fixed bug related to
regexwhen using a comma (,) in a multi-entryAdmission Control user criteria. - Fixed bug where the CVE scan of
jarpackages would not show all packages affected by a same CVE. Now all occurences are reported. - Remediates following CVEs:
| CVE | Applies to | Impact |
|---|---|---|
| CVE-2024-35195 | python:requests | π‘ Medium |
| CVE-2024-21011 | openjdk11 | π’ Low |
| CVE-2024-21012 | openjdk11 | π’ Low |
| CVE-2024-21068 | openjdk11 |