Skip to main content
Version: Latest

Security Advisories and CVEs

Rancher is committed to informing the community of security issues in our products. Rancher will publish security advisories and CVEs (Common Vulnerabilities and Exposures) for issues we have resolved. New security advisories are also published in Rancher's GitHub security page.

IDDescriptionDateResolution
CVE-2024-58260Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the Manage Users permission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use.25 Sep 2025Rancher v2.12.2, v2.11.6, v2.10.10, and v2.9.12
CVE-2024-58267The Rancher CLI is modified to print the requestId more visibly than as part of the login URL. It also adds a cli=true origin marker to the URL. The dashboard is modified to recognize the presence of the requestId and uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly.25 Sep 2025Rancher v2.12.2, v2.11.6, v2.10.10, and v2.9.12
CVE-2025-54468Impersonate-* headers are removed for requests made through the /meta/proxy Rancher endpoint (e.g. when cloud credentials are being created) as the headers may contain identifiable and/or sensitive information.25 Sep 2025Rancher v2.12.2, v2.11.6, v2.10.10, and v2.9.12
CVE-2024-58259POSTs to the Rancher API endpoints are now limited to 1 Mi; this is configurable through the settings if you need a larger limit. The Rancher authentication endpoints are configured independently of the main public API (as you might need bigger payloads in the other API endpoints). Suppose you need to increase the maximum allowed payload for authentication. In that case, you can set the environment variable CATTLE_AUTH_API_BODY_LIMIT to a quantity, e.g., 2 Mi, which would allow larger payloads for the authentication endpoints.28 Aug 2025Rancher v2.12.1, v2.11.5, v2.10.9 and v2.9.11
CVE-2024-52284Following a recent change excluding Helm values files from bundles, an edge case subsisted where the values files referenced in fleet.yaml with your directory name (e.g., my-dir/values.yaml instead of values.yaml) would not be excluded, which would potentially expose confidential data in bundle resources. Helm values files are now excluded from bundle resources regardless of how you reference them.28 Aug 2025Rancher v2.12.1, v2.11.5 and v2.10.9