High severityOSV Advisory· Published Jul 6, 2026· Updated Jul 6, 2026
SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components
CVE-2026-44937
Description
Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/fleetGo | >= 0.15.0, < 0.15.2 | 0.15.2 |
github.com/rancher/fleetGo | >= 0.14.0, < 0.14.6 | 0.14.6 |
github.com/rancher/fleetGo | >= 0.13.0, < 0.13.11 | 0.13.11 |
github.com/rancher/fleetGo | >= 0.12.0, < 0.12.15 | 0.12.15 |
Affected products
3- Range: <0.15.2, <0.14.6, <0.13.11, <0.12.5
Patches
Vulnerability mechanics
References
2- github.com/advisories/GHSA-jmf4-m7j9-g72rghsaADVISORY
- github.com/rancher/fleet/security/advisories/GHSA-jmf4-m7j9-g72rghsavendor-advisoryWEB
News mentions
0No linked articles in our index yet.