Rancher Fleet是Rancher公司的一款容器集群监控与管理平台。 Rancher Fleet存在服务端请求伪造漏洞,该漏洞源于使用未认证的Webhook时可能导致Webhook请求伪造,远程攻击者可利用此漏洞造成拒绝服务或对其他存储库进行降级攻击。以下版本受到影响:0.15.2版本之前的0.15.x版本、0.14.6版本之前的0.14.x版本、0.13.11版本之前的0.13.x版本和0.12.5版本之前的0.12.x版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44936 | 5.0 MEDIUM | Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml |
| CVE-2026-44934 | Exposed tokens in SUSE Rancher AI Agent logs |
No comments yet