CVE-2026-44937 Details
Description
Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system.
A vulnerability exists in SUSE Rancher Fleet versions 0.15.0 prior to 0.15.2, 0.14.0 prior to 0.14.6, 0.13.0 prior to 0.13.11, and 0.12.0 prior to 0.12.5. When webhooks are configured without authentication, remote attackers can forge webhook requests. This exploitation can lead to a denial-of-service condition by causing continuous re-cloning of repositories, which increases network traffic and depletes resources on the management cluster. Additionally, the vulnerability could be used to perform a downgrade attack on services by reverting them to any historical revision available in the targeted Git repository, assuming the attacker has read access to that repository.
Users can upgrade to Fleet versions 0.15.2, 0.14.6, 0.13.11, or 0.12.15, all of which address this vulnerability by sanitizing the URL and path components of webhook requests. If an upgrade is not possible, it is recommended to enable webhooks with a shared secret.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rancher/fleet/security/advisories/GHSA-jmf4-m7j9-g72r | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| suse rancher fleet | >= 0.12.0, < 0.12.15 >= 0.13.0, < 0.13.11 >= 0.14.0, < 0.14.6 >= 0.15.0, < 0.15.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 6, 2026 | New CVE Received | [email protected] |