VYPR

Rancher Manager

by Rancher

Source repositories

CVEs (2)

  • CVE-2026-59675Aug 5, 2026
    risk 0.00cvss epss 0.00

    When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because the audit middleware is positioned earlier in the handler chain than Rancher's APIBodyLimitingHandler, the body-size cap…

  • CVE-2026-44939Jun 19, 2026
    risk 0.00cvss epss 0.01

    A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.