CVE-2026-55996
Published:August 05, 2026
Updated:September 01, 2026
A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate any hostname presented via Server Name Indication (SNI) in incoming TLS requests.
An unauthenticated attacker with network access within the affected cluster could send a large number of TLS requests with distinct hostnames, causing the serving certificate to accumulate an unbounded number of Subject Alternative Names (SANs). Eventually, the certificate grows large enough that TLS handshakes fail with an excessive message size error, causing a denial of service on the affected listeners.
Affected Packages
https://github.com/rancher/rancher.git (GITHUB):
Affected version(s) >=v2.11.0 <v2.11.16Fix Suggestion:
Update to version v2.11.16https://github.com/rancher/rancher.git (GITHUB):
Affected version(s) >=v2.12.0 <v2.12.12Fix Suggestion:
Update to version v2.12.12https://github.com/rancher/rancher.git (GITHUB):
Affected version(s) >=v2.13.0 <v2.13.8Fix Suggestion:
Update to version v2.13.8https://github.com/rancher/rancher.git (GITHUB):
Affected version(s) >=v2.14.0 <v2.14.4Fix Suggestion:
Update to version v2.14.4github.com/rancher/rancher (GO):
Affected version(s) >=v0.0.0-20250731022323-8815e66bf2e4 <v0.0.0-20260730195259-3bc84195ee88Fix Suggestion:
Update to version v0.0.0-20260730195259-3bc84195ee88github.com/rancher/rancher (GO):
Affected version(s) >=v0.0.0-20260326190150-19d8a9c03fde <v0.0.0-20260730195249-79b003279fecFix Suggestion:
Update to version v0.0.0-20260730195249-79b003279fecgithub.com/rancher/rancher (GO):
Affected version(s) >=v0.0.0-20250331174853-4b8ab8c48d68 <v0.0.0-20260730195307-e6c19548ededFix Suggestion:
Update to version v0.0.0-20260730195307-e6c19548ededgithub.com/rancher/rancher (GO):
Affected version(s) >=v0.0.0-20251125015639-f94ac947f75e <v0.0.0-20260730195254-853a0e93a1caFix Suggestion:
Update to version v0.0.0-20260730195254-853a0e93a1caRelated Resources (4)
Do you need more information?
Contact UsCVSS v4
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
NONE
Vulnerable System Availability
LOW
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
4.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW
Weakness Type (CWE)
Allocation of Resources Without Limits or Throttling
EPSS
Base Score:
0.15