CVE-2025-71261
published 2026-06-16CVE-2025-71261: An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake…
PriorityP353high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
0.21%
10.9th percentile
An attacker with network-level access between the SUSE Virtualization
and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it
to bypass TLS as a security control.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | harvester_harvester | >= 0 < 1.8.0 | 1.8.0 |
| suse | harvester | < 1.8 | 1.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SUSE Harvester up to 1.7 TLS Handshake certificate validation (GHSA-pgh9-mpwc-8jjf)
vuldb·2026-06-16·CVSS 8.6
CVE-2025-71261 [HIGH] SUSE Harvester up to 1.7 TLS Handshake certificate validation (GHSA-pgh9-mpwc-8jjf)
A vulnerability was found in SUSE Harvester up to 1.7. It has been rated as problematic. This affects an unknown function of the component TLS Handshake Handler. The manipulation leads to improper certificate validation.
This vulnerability is uniquely identified as CVE-2025-71261. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
ghsa·2026-05-06
CVE-2025-71261 [HIGH] CWE-295 Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
### Impact
A vulnerability has been identified in the [SUSE Virtualization (Harvester) Rancher integration mechanism](https://docs.harvesterhci.io/v1.7/rancher/rancher-integration) where by default the registration client uses an insecure TLS option that fails to verify the remote server’s certificate. This security gap could allow the execution of a man-in-the-middle (MitM) attack against SUSE Virtualization.
An attacker with network-level access between the SUSE Virtualization and Rancher Manager could interfere with the TLS handshake and abuse it to bypass TLS as a security control. The registration client could be misled to send cluster registration requests to an impersonated remote service. Additionally
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published