Junglewise Threat Intelligence

CVE-2026-44937: SUSE Rancher Fleet webhook request forgery via regex injection

CVE-2026-44937 · Severity: high · CVSS 7.5 · Published 2026-07-06

Technologies: SUSE Rancher Fleet, github.com/rancher/fleet (Go). Vendors: Go, Suse.

Executive brief

SUSE Rancher Fleet, a tool used to manage large-scale Kubernetes deployments, contains a vulnerability in how it handles update notifications (webhooks). If these notifications are not protected by a secret password, an attacker can send fake messages to the system. This can be used to force the system into a loop of downloading data, causing a service outage, or to force applications to revert to older, potentially insecure versions of their code.

Technical details

A vulnerability in SUSE Rancher Fleet arises when the webhook endpoint is configured without a shared secret, leading to unsanitized repository URL components. The root cause is a lack of escaping for the URL and path received from webhooks, which allows for regex injection. A remote, unauthenticated attacker can forge webhook requests to trigger continuous repository re-cloning (Denial of Service) or force a downgrade of running services to any historical revision available in the remote Git repository. This exploit is possible even if the attacker does not know the specific repository path, provided they have read access to the target Git repository. Patches are available in versions 0.15.2, 0.14.6, 0.13.11, and 0.12.15.

Affected products

  • SUSE Rancher Fleet 0.15.0 to 0.15.1, 0.14.0 to 0.14.5, 0.13.0 to 0.13.10, 0.12.0 to 0.12.14

Timeline

  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-07-06: disclosed: CVE published to NVD

References

Related threats