cbcvebase.
CVE-2026-55996
published 2026-08-05

CVE-2026-55996: A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters…

PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.15%
4.8th percentile
A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate any hostname presented via Server Name Indication (SNI) in incoming TLS requests. An unauthenticated attacker with network access within the affected cluster could send a large number of TLS requests with distinct hostnames, causing the serving certificate to accumulate an unbounded number of Subject Alternative Names (SANs). Eventually, the certificate grows large enough that TLS handshakes fail with an excessive message size error, causing a denial of service on the affected listeners.

Affected

4 ranges
VendorProductVersion rangeFixed in
suserancher>= 2.11.0 < 2.11.162.11.16
suserancher>= 2.12.0 < 2.12.122.12.12
suserancher>= 2.13.0 < 2.13.82.13.8
suserancher>= 2.14.0 < 2.14.42.14.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.