Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SUSE — Vulnerabilities & Security Advisories 214

Browse all 214 CVE security advisories affecting SUSE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SUSE operates primarily as a provider of enterprise Linux distributions and cloud-native solutions, serving critical infrastructure in hybrid and multi-cloud environments. With 185 recorded CVEs, its vulnerability profile reflects the complexity of managing large-scale open-source codebases. Historically, common flaw classes include remote code execution (RCE), buffer overflows, and privilege escalation vulnerabilities, often stemming from misconfigurations or outdated dependencies within its core operating system components. Notable security characteristics involve its focus on container security and Kubernetes integration, which introduces attack surfaces related to orchestration layers. While no single catastrophic incident defines its history, the sheer volume of vulnerabilities highlights the ongoing challenge of maintaining security in widely deployed, long-term support releases. This necessitates rigorous patch management and continuous monitoring to mitigate risks associated with its extensive ecosystem of integrated services and third-party libraries.

Found 67 results / 214Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-44945 Cross-Cluster Impersonation Confused-Deputy Privilege Escalation — RancherCWE-441 9.1 Critical2026-08-05
CVE-2026-55998 Cluster Existence Oracle via Unauthenticated Import Endpoint — RancherCWE-204 5.3 Medium2026-08-05
CVE-2026-59675 Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service — RancherCWE-770 7.5 High2026-08-05
CVE-2026-55996 Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agent — Rancher 4.3 Medium2026-08-05
CVE-2026-44938 Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent — RancherCWE-522 8.8 High2026-07-07
CVE-2026-44937 SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components — RancherCWE-918--2026-07-06
CVE-2026-44936 Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml — RancherCWE-918 5.0 Medium2026-07-06
CVE-2026-44934 Exposed tokens in SUSE Rancher AI Agent logs — RancherCWE-215--2026-07-06
CVE-2026-44935 Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer — RancherCWE-1287 9.9 Critical2026-07-02
CVE-2026-44948 Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler — RancherCWE-23--2026-06-30
CVE-2026-44949 Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhook — RancherCWE-306--2026-06-30
CVE-2026-44947 Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher — RancherCWE-281--2026-06-30
CVE-2026-44946 SAML Authentication Replay in Rancher — RancherCWE-294--2026-06-30
CVE-2026-41053 Over-inclusive team membership expansion in GitHub App authentication provider for Rancher — RancherCWE-303 8.8 High2026-06-30
CVE-2026-41052 Rancher Privilege Escalation from Project Owner to Host — RancherCWE-305--2026-06-29
CVE-2026-44939 Command injection through unsanitized YAML parameter in Rancher — RancherCWE-95--2026-06-19
CVE-2026-41050 Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering — RancherCWE-863 9.9 Critical2026-05-13
CVE-2026-25705 Rancher Extensions have arbitrary file access via path traversal — rancherCWE-35 8.4 High2026-05-13
CVE-2025-62879 Rancher Backup Operator pod's logs leak S3 tokens — RancherCWE-532 6.8 Medium2026-03-04
CVE-2025-62878 Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern — RancherCWE-23 9.9 Critical2026-02-25
CVE-2025-67601 Rancher CLI skips TLS verification on Rancher CLI login command — rancherCWE-295 8.3 High2026-02-25
CVE-2024-58269 Rancher exposes sensitive information through audit logs — rancherCWE-532 4.3 Medium2025-10-29
CVE-2023-32199 Rancher user retains access to clusters despite Global Role removal — rancherCWE-281 4.3 Medium2025-10-29
CVE-2024-58260 Rancher update on users can deny the service to the admin — rancherCWE-863 7.6 High2025-10-02
CVE-2024-58267 Rancher CLI SAML authentication is vulnerable to phishing attacks — rancherCWE-345 8.0 High2025-10-02
CVE-2025-54468 Rancher sends sensitive information to external services through the `/meta/proxy` endpoint — rancherCWE-200 4.7 Medium2025-10-02
CVE-2024-58259 Rancher affected by unauthenticated Denial of Service — rancherCWE-770 8.2 High2025-09-02
CVE-2024-52284 Rancher Fleet Helm Values are stored inside BundleDeployment in plain text — RancherCWE-312 7.7 High2025-09-02
CVE-2023-32197 Rancher's External RoleTemplates can lead to privilege escalation — rancherCWE-269 6.6 Medium2025-04-16
CVE-2024-22036 Rancher Remote Code Execution via Cluster/Node Drivers — rancherCWE-269 9.1 Critical2025-04-16

This page lists every published CVE security advisory associated with SUSE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.