Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75036— Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing

Quick assessment

Affected
SUSE Fleet
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Fleet 的 Helm 模板预处理过程中发现了一个安全漏洞。由 Fleet 控制器评估的模板可以访问到管理集群之外的网络资源。能够向 资源所引用的仓库提供 bundle 内容的用户,可以导致 Fleet 控制器: 泄露模板化上下文中可用的集群元数据。 揭示从控制器网络位置可达的主机信息。 由于信息泄露的通道是 DNS 名称解析,因此在其他出站流量受限的环境中,该漏洞可能仍然有效。泄露的信息仅限于暴露给 Fleet 模板化上下文的值以及名称解析结果。受管集群的完整性和可用性不受影响。 此问题影响以下版本的 Fl

CVSS 5.3 · Medium

Affected Version Matrix 5

VendorProduct Version RangeStatus
SUSE Fleet 0.12.0< 0.12.19 affected
0.13.0< 0.13.15 affected
0.14.0< 0.14.10 affected
0.15.0< 0.15.6 affected
0.16.0< 0.16.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75036

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing
Source: CVE Program / CVE List V5
Vulnerability Description
A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to: - Disclose cluster metadata available to the templating context. - Reveal information about hosts reachable from the controller's network position. Because the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected. This issue affects Fleet: from 0.12.0 before 0.12.19, from 0.13.0 before 0.13.15, from 0.14.0 before 0.14.10, from 0.15.0 before 0.15.6, and from 0.16.0 before 0.16.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SUSE Fleet 0.12.0 ~ 0.12.19 -

II. Public POCs for CVE-2026-75036

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75036

登录查看更多情报信息。

Vendor Advisories for CVE-2026-75036 (1)

Same Patch Batch · SUSE · 2026-09-03 · 6 CVEs total

CVE-2026-71404 8.7 HIGH Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation o
CVE-2026-75033 7.7 HIGH Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing
CVE-2026-75035 7.7 HIGH Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scop
CVE-2026-75034 7.4 HIGH Rancher: SAML Assertion Replay
CVE-2026-71403 6.1 MEDIUM Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind

IV. Related Vulnerabilities

V. Comments for CVE-2026-75036

No comments yet


Leave a comment