VYPR
High severityOSV Advisory· Published Jul 6, 2026· Updated Jul 6, 2026

SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

CVE-2026-44937

Description

Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/rancher/fleetGo
>= 0.15.0, < 0.15.20.15.2
github.com/rancher/fleetGo
>= 0.14.0, < 0.14.60.14.6
github.com/rancher/fleetGo
>= 0.13.0, < 0.13.110.13.11
github.com/rancher/fleetGo
>= 0.12.0, < 0.12.150.12.15

Affected products

3
  • Rancher/FleetOSV2 versions
    v0.15.2-rc.2, pkg/apis/v0.15.2-rc.2, v0.12.15-rc.2, …+ 1 more
    • (no CPE)range: v0.15.2-rc.2, pkg/apis/v0.15.2-rc.2, v0.12.15-rc.2, …
    • (no CPE)range: <0.15.2, <0.14.6, <0.13.11, <0.12.5
  • Range: <0.15.2, <0.14.6, <0.13.11, <0.12.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.