Security Advisories and CVEs
Rancher is committed to informing the community of security issues in our products. Rancher will publish security advisories and CVEs (Common Vulnerabilities and Exposures) for issues we have resolved. New security advisories are also published in Rancher's GitHub security page.
| ID | Description | Date | Resolution | 
|---|---|---|---|
| CVE-2023-32199 | Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation authz.cluster.cattle.io/admin-globalrole-missing=true. | 23 Oct 2025 | Rancher v2.12.3 and v2.11.7 | 
| CVE-2024-58269 | The Rancher audit log redaction process has changed to the following: 
 | 23 Oct 2025 | Rancher v2.12.3 | 
| CVE-2024-58260 | Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the Manage Userspermission could potentially deny any user, including admins, from logging in. To prevent this, usernames have been made immutable once set, and it is not possible to update or create a user with a username that is already in use. | 25 Sep 2025 | Rancher v2.12.2, v2.11.6, v2.10.10, and v2.9.12 | 
| CVE-2024-58267 | The Rancher CLI is modified to print the requestIdmore visibly than as part of the login URL. It also adds acli=trueorigin marker to the URL. The dashboard is modified to recognize the presence of therequestIdand uses that to show a warning message to the user, asking for verification that they initiated a CLI login with the related Id. The non-presence of the origin marker enables the dashboard to distinguish between the modified CLI and older CLI’s, and adjust the message accordingly. | 25 Sep 2025 | Rancher v2.12.2, v2.11.6, v2.10.10, and v2.9.12 | 
| CVE-2025-54468 | Impersonate-*headers are removed for requests made through the/meta/proxyRancher endpoint (e.g. when cloud credentials are being created) as the headers may contain identifiable and/or sensitive information. | 25 Sep 2025 | Rancher v2.12.2, v2.11.6, v2.10.10, and v2.9.12 | 
| CVE-2024-58259 | POSTs to the Rancher API endpoints are now limited to 1 Mi; this is configurable through the settings if you need a larger limit. The Rancher authentication endpoints are configured independently of the main public API (as you might need bigger payloads in the other API endpoints). Suppose you need to increase the maximum allowed payload for authentication. In that case, you can set the environment variable CATTLE_AUTH_API_BODY_LIMITto a quantity, e.g., 2 Mi, which would allow larger payloads for the authentication endpoints. | 28 Aug 2025 | Rancher v2.12.1, v2.11.5, v2.10.9 and v2.9.11 | 
| CVE-2024-52284 | Following a recent change excluding Helm values files from bundles, an edge case subsisted where the values files referenced in fleet.yamlwith your directory name (e.g.,my-dir/values.yamlinstead ofvalues.yaml) would not be excluded, which would potentially expose confidential data in bundle resources. Helm values files are now excluded from bundle resources regardless of how you reference them. | 28 Aug 2025 | Rancher v2.12.1, v2.11.5 and v2.10.9 |