VYPR
Medium severity4.7GHSA Advisory· Published Oct 2, 2025· Updated Apr 15, 2026

CVE-2025-54468

CVE-2025-54468

Description

A vulnerability has been identified within Rancher Manager whereby Impersonate-Extra-* headers are being sent to an external entity, for example amazonaws.com, via the /meta/proxy Rancher endpoint. These headers may contain identifiable and/or sensitive information e.g. email addresses.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/rancher/rancherGo
>= 2.12.0, < 2.12.22.12.2
github.com/rancher/rancherGo
>= 2.11.0, < 2.11.62.11.6
github.com/rancher/rancherGo
>= 2.10.0, < 2.10.102.10.10
github.com/rancher/rancherGo
>= 2.9.0, < 2.9.122.9.12

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.