Documentation survey

Security Advisories and CVEs

Rancher is committed to informing the community of security issues in our products. Rancher will publish security advisories and CVEs (Common Vulnerabilities and Exposures) for issues we have resolved. New security advisories are also published in Rancher’s GitHub security page.

ID Description Date Resolution

CVE-2024-58259

POSTs to the Rancher API endpoints are now limited to 1 Mi; this is configurable through the settings if you need a larger limit. The Rancher authentication endpoints are configured independently of the main public API (as you might need bigger payloads in the other API endpoints). Suppose you need to increase the maximum allowed payload for authentication. In that case, you can set the environment variable CATTLE_AUTH_API_BODY_LIMIT to a quantity, e.g., 2 Mi, which would allow larger payloads for the authentication endpoints.

28 Aug 2025

Rancher v2.12.1, v2.11.5, v2.10.9 and v2.9.11

CVE-2023-32198

Following a recent change excluding Helm values files from bundles, an edge case subsisted where the values files referenced in fleet.yaml with your directory name (e.g., my-dir/values.yaml instead of values.yaml) would not be excluded, which would potentially expose confidential data in bundle resources. Helm values files are now excluded from bundle resources regardless of how you reference them.

28 Aug 2025

Rancher v2.12.1, v2.11.5 and v2.10.9