Suse Rancher Fleet vulnerabilities
3 known vulnerabilities affecting suse/rancher_fleet.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-44935P2CRITICALCVSS 9.9≥ 0.12.0, < 0.12.15≥ 0.13.0, < 0.13.11+2 more2026-07-02
CVE-2026-44935 [CRITICAL] CWE-1287 CVE-2026-44935: Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.1
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
nvd
CVE-2026-44937P3HIGHCVSS 8.2≥ 0.12.0, < 0.12.15≥ 0.13.0, < 0.13.11+2 more2026-07-06
CVE-2026-44937 [HIGH] CWE-918 CVE-2026-44937: Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.1
Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system.
nvd
CVE-2026-44936P4MEDIUMCVSS 5.0≥ 0.12.0, < 0.12.15≥ 0.13.0, < 0.13.11+2 more2026-07-06
CVE-2026-44936 [MEDIUM] CWE-918 CVE-2026-44936: Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fl
Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able t
nvd