github.com/rancher/rancher vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-41052Criticalgithub.com/rancher/rancher: Rancher has Privilege Escalation from Project Owner to HostCVE-2026-41053Highgithub.com/rancher/rancher: Rancher has over-inclusive team membership expansion in GitHub App authentication providerCVE-2026-44939Criticalgithub.com/rancher/rancher: Rancher vulnerable to command injection through unsanitized YAML parameterCVE-2026-25705Highgithub.com/rancher/rancher: Rancher Extensions have arbitrary file access via path traversalCVE-2021-25320Criticalgithub.com/rancher/rancher: Rancher cloud credentials can be used through proxy API by users without accessGHSA-HWM2-4PH6-W6M5Highgithub.com/rancher/rancher: Rancher's restricted PodSecurityPolicy does not prevent containers from running as a privileged userCVE-2022-21951Mediumgithub.com/rancher/rancher: Rancher's weave CNI password is not configured when a cluster is created from an RKE templateCVE-2022-31247Criticalgithub.com/rancher/rancher: Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)CVE-2021-36783Criticalgithub.com/rancher/rancher: Rancher doesn't properly sanitize credentials in cluster template answersCVE-2023-22648Highgithub.com/rancher/rancher: Rancher's Azure AD permission changes are not reflected on active sessionsCVE-2025-67601Highgithub.com/rancher/rancher: Rancher CLI skips TLS verification on Rancher CLI login commandCVE-2024-58269Mediumgithub.com/rancher/rancher: Rancher exposes sensitive information through audit logsCVE-2023-32199Mediumgithub.com/rancher/rancher: Rancher user retains access to clusters despite Global Role removalCVE-2024-58260Highgithub.com/rancher/rancher: Rancher update on users can deny the service to the adminCVE-2024-58267Highgithub.com/rancher/rancher: Rancher CLI SAML authentication is vulnerable to phishing attacksCVE-2025-54468Mediumgithub.com/rancher/rancher: Rancher sends sensitive information to external services through the `/meta/proxy` endpointCVE-2024-58259Highgithub.com/rancher/rancher: Rancher affected by unauthenticated Denial of ServiceCVE-2024-22031Highgithub.com/rancher/rancher: Rancher users who can create Projects can gain access to arbitrary projectsCVE-2025-23391Criticalgithub.com/rancher/rancher: Rancher: Restricted Administrator can change Administrator's passwordsCVE-2025-23389Highgithub.com/rancher/rancher: Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First LoginCVE-2025-23388Highgithub.com/rancher/rancher: Rancher allows an unauthenticated stack overflow in /v3-public/authproviders APICVE-2025-23387Mediumgithub.com/rancher/rancher: Rancher's SAML-based login via CLI can be denied by unauthenticated usersCVE-2024-52281Highgithub.com/rancher/rancher: Rancher UI has Stored Cross-site Scripting vulnerabilityCVE-2024-52282Mediumgithub.com/rancher/rancher: Rancher Helm Applications may have sensitive values leakedCVE-2024-22036Criticalgithub.com/rancher/rancher: Rancher Remote Code Execution via Cluster/Node Drivers

Stop the waste.
Protect your environment with Kodem.