PT-2025-35332 · Suse · Rancher Manager
Published
2025-08-29
·
Updated
2025-09-01
·
CVE-2024-58259
8.2
High
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions:
Rancher Manager versions 2.9.12, 2.10.9, 2.11.5, and 2.12.1
Description:
A high-severity Denial of Service (DoS) flaw exists in Rancher Manager, allowing attackers to crash servers by sending oversized API requests to certain public (unauthenticated) and authenticated API endpoints. The vulnerability occurs because the software does not enforce request body size limits, allowing malicious users to send excessively large payloads that exhaust server memory. This can disrupt Rancher’s availability, impacting administrative and user operations. The issue affects both unauthenticated `/v3-public/*` endpoints and several authenticated APIs.
Recommendations:
Upgrade to Rancher Manager version 2.9.12 to address the vulnerability.
Upgrade to Rancher Manager version 2.10.9 to address the vulnerability.
Upgrade to Rancher Manager version 2.11.5 to address the vulnerability.
Upgrade to Rancher Manager version 2.12.1 to address the vulnerability.
If upgrading is not immediately possible, manually set request body size limits, such as by using an nginx-ingress controller and only allowing requests via the ingress.
Fix
Allocation of Resources Without Limits
Weakness Enumeration
Related Identifiers
Affected Products
References · 12
- https://osv.dev/vulnerability/GHSA-4h45-jpvh-6p5j · Vendor Advisory
- https://github.com/rancher/rancher⭐ 24612 🔗 3092 · Note
- https://github.com/rancher/rancher/commit/aee95d4e2a41ba2df6f88c9634d4fe1f42dee4d9⭐ 24612 🔗 3092 · Note
- https://github.com/rancher/rancher/releases/tag/v2.9.11⭐ 24612 🔗 3092 · Note
- https://github.com/rancher/rancher/security/advisories/GHSA-4h45-jpvh-6p5j⭐ 24612 🔗 3092 · Note
- https://github.com/rancher/rancher/releases/tag/v2.11.5⭐ 24612 🔗 3092 · Note
- https://github.com/rancher/rancher/releases/tag/v2.12.1⭐ 24612 🔗 3092 · Note
- https://github.com/rancher/rancher/releases/tag/v2.10.9⭐ 24612 🔗 3092 · Note
- https://twitter.com/fridaysecurity/status/1962311717045551306 · Twitter Post
- https://twitter.com/Iambivash007/status/1962377809122509269 · Twitter Post
- https://t.me/pentestingnews/67258 · Telegram Post
- https://twitter.com/the_yellow_fall/status/1962345053306957911 · Twitter Post