Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able to push to fleet monitored git repos to leak helm access credentials.
References
| Link | Resource |
|---|---|
| https://github.com/advisories/GHSA-hx4v-cxpf-vh8m | Exploit Third Party Advisory Mitigation |
Configurations
Configuration 1 (hide)
|
History
09 Jul 2026, 20:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:* | |
| First Time |
Suse
Suse rancher Fleet |
|
| References | () https://github.com/advisories/GHSA-hx4v-cxpf-vh8m - Exploit, Third Party Advisory, Mitigation |
06 Jul 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-06 11:16
Updated : 2026-07-09 20:34
NVD link : CVE-2026-44936
Mitre link : CVE-2026-44936
CVE.ORG link : CVE-2026-44936
JSON object : View
Products Affected
suse
- rancher_fleet
CWE
CWE-918
Server-Side Request Forgery (SSRF)
