These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-44945 is a critical vulnerability in Rancher's impersonation middleware, allowing an authenticated user with the default user global role to escalate privileges and gain full administrative access to the Rancher control plane and downstream clusters. This issue affects Rancher versions 2.11.0-2.11.16, 2.12.0-2.12.12, 2.13.0-2.13.8, and 2.14.0-2.14.2. The vulnerability has a CVSS score of 9.1 and [truncated]
The CVE-2026-59675 vulnerability affects Rancher Manager, allowing an unauthenticated attacker to send large request bodies to public login endpoints, potentially exhausting available memory and terminating the Rancher Manager plane process. This issue arises when API audit logging is enabled and no size limit is enforced on login endpoints. The vulnerability has a CVSS score of 7.5 and is classified as H [truncated]
The CVE-2026-55998 vulnerability is a nil pointer dereference issue in the /v3/import/{token}_{clusterId}.yaml endpoint. This endpoint retrieves a cluster object before validating the token, leading to a potential enumeration oracle. When a valid cluster ID with private registry secrets is provided, the request returns an HTTP 502 Bad Gateway response, whereas non-existent cluster IDs return an HTTP 200 r [truncated]
A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher, affecting the cattle-cluster-agent component and the Rancher server itself. The dynamiclistener library is used to serve TLS traffic without an effective CN filter configured, allowing an unauthenticated attacker with network access to cause a denial of service. The vulnerability has a CVSS score of 4.3 and a severity o [truncated]
A Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability was found in SUSE Virtual Machine Driver Pack. The issue allows an attacker with registry modification capabilities to impact driver integrity. Currently, there is no known feasible exploitation method. This vulnerability affects Virtual Machine Driver Pack versions before e7a602ec232756ead019bdf19d6d3b9d010cc94b. The CVS [truncated]
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1. The vulnerability exists due to improper handling of symbolic links in the suricata package, allowing a local user to escalate privileges to root. Users of openSUSE Tumbleweed with suricata package inst [truncated]
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows t [truncated]
CVE-2026-44937 involves potential forgery of webhook requests in SUSE Rancher Fleet. The vulnerability affects versions 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11, and 0.12 before 0.12.5. Remote attackers could exploit this to cause a denial of service or a downgrade attack on other repositories on the system. This is a high-severity vulnerability with a CVSS score of 8.3. Users of affect [truncated]
CVE-2026-44936 is a vulnerability in SUSE Rancher Fleet's bundle reader. When the helmRepoURLRegex field isn't set on a GitRepo resource, it forwards Helm authentication credentials to any URL specified in the helm.repo field of a fleet.yaml file. This allows attackers able to push to fleet monitored git repos to leak Helm access credentials. The vulnerability has a CVSS score of 5 and is classified as ME [truncated]
CVE-2026-44941 is a HIGH severity vulnerability in libzypp, a package manager library used in openSUSE and SUSE Linux distributions. The vulnerability allows an attacker to inject or overwrite files in the target system as root by supplying a malicious repository. This issue arises from a relative path traversal in the 'keyhint' option in repomd.xml parsing of libzypp before version 17.38.12. The vulnerab [truncated]
A path traversal vulnerability was found in libzypp before 17.38.13 in the 17.x series or before 16.22.19. The vulnerability occurs in the handling of the 'path' component of .repo files. This could be exploited by attackers to fill directories on the system outside of the zypp cache with content. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Users of SUSE products that u [truncated]
CVE-2026-44932 is a HIGH severity vulnerability with a CVSS score of 8.8. The vulnerability exists in the wicked DHCP client before version 0.6.79, where unsanitized strings from DHCP replies can be used by attackers operating a malicious DHCP server to execute code on the local machine. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2025-71261 is a high-severity vulnerability in SUSE Harvester that allows an attacker with network-level access between the SUSE Virtualization and Rancher Manager to interfere with the TLS handshake and bypass TLS as a security control. The vulnerability has a CVSS score of 8.6 and is classified as HIGH.
CVE-2026-44933 describes a weakness in PluginScript’s attempt to chroot plugins to repoManagerRoot. In common configurations, that target may be the system root (/), or the process may be run with --root, making the chroot ineffective. When the chroot is a no-op, traversed paths may reach host binaries such as /bin/bash and execute them with root privileges. NVD currently lists the vulnerability as Deferr [truncated]
CVE-2026-41054 is a local privilege-escalation issue in the command-socket handling path described for src/havegecmd.c. According to the NVD record, the code checks the connecting user on the abstract UNIX socket and prepares a negative acknowledgement for non-root callers, but execution continues into the command switch anyway. That means an unprivileged local user may be able to reach privileged command [truncated]
CVE-2016-2318 describes a denial-of-service condition in GraphicsMagick 1.3.23 triggered by crafted SVG content. NVD records the weakness as CWE-476 (NULL pointer dereference) and rates the issue CVSS 3.0 5.5/Medium. The CVE data ties the issue to SVG parsing/rendering paths including DrawImage, SVGStartElement, and TraceArcPath. Systems that process untrusted SVG files through affected GraphicsMagick bui [truncated]
CVE-2016-2317 is a denial-of-service vulnerability in GraphicsMagick 1.3.23 caused by multiple buffer overflows while processing crafted SVG content. The issue is described as affecting the TracePoint function in magick/render.c, GetToken in magick/utility.c, and GetTransformTokens in coders/svg.c. According to the NVD record, the impact is availability-only (CVSS 5.5, medium), and the published CVSS vect [truncated]