github.com/rancher/rancher vulnerabilities
CVEs whose affected-version data names the github.com/rancher/rancher package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
23 CVEsRSS
CVE-2026-44939Critical· 9.6Rancher vulnerable to command injection through unsanitized YAML parameter
Rancher vulnerable to command injection through unsanitized YAML parameter
CVE-2026-41053High· 8.8Rancher has over-inclusive team membership expansion in GitHub App authentication provider
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
CVE-2026-41052Critical· 8.4Rancher has Privilege Escalation from Project Owner to Host
Rancher has Privilege Escalation from Project Owner to Host
CVE-2026-25705High· 8.4Rancher Extensions have arbitrary file access via path traversal
Rancher Extensions have arbitrary file access via path traversal
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access
Rancher cloud credentials can be used through proxy API by users without access
CVE-2022-21951Medium· 6.8Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
CVE-2023-22648High· 8.0Rancher's Azure AD permission changes are not reflected on active sessions
Rancher's Azure AD permission changes are not reflected on active sessions
CVE-2021-36783Critical· 9.9Rancher doesn't properly sanitize credentials in cluster template answers
Rancher doesn't properly sanitize credentials in cluster template answers
CVE-2022-31247Critical· 9.1Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
CVE-2025-23387Medium· 5.3Rancher's SAML-based login via CLI can be denied by unauthenticated users
Rancher's SAML-based login via CLI can be denied by unauthenticated users
CVE-2024-52281High· 8.9Rancher UI has Stored Cross-site Scripting vulnerability
Rancher UI has Stored Cross-site Scripting vulnerability
CVE-2023-32196Critical· 9.1Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
CVE-2021-36775High· 8.0Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
CVE-2021-31999High· 8.8Rancher Privilege escalation vulnerability via malicious "Connection" header
Rancher Privilege escalation vulnerability via malicious "Connection" header
CVE-2021-25318High· 8.8Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
CVE-2023-22647Critical· 9.9Rancher vulnerable to Privilege Escalation via manipulation of Secrets
Rancher vulnerable to Privilege Escalation via manipulation of Secrets
CVE-2020-10676High· 8.8Rancher users retain access after moving namespaces into projects they don't have access to
Rancher users retain access after moving namespaces into projects they don't have access to
CVE-2022-43760High· 8.4Rancher UI has multiple Cross-Site Scripting (XSS) issues
Rancher UI has multiple Cross-Site Scripting (XSS) issues
CVE-2023-22651Critical· 9.9Rancher Webhook is misconfigured during upgrade process
Rancher Webhook is misconfigured during upgrade process
CVE-2021-36782Critical· 9.9PoCRancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
CVE-2019-12274High· 8.8Rancher Privilege Escalation Vulnerability
Rancher Privilege Escalation Vulnerability
CVE-2021-25313Medium· 6.1Rancher Cross-site Scripting Vulnerability
Rancher Cross-site Scripting Vulnerability
GHSA-wm2r-rp98-8pmhLowExposure of SSH credentials in Rancher/Fleet
Exposure of SSH credentials in Rancher/Fleet