Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-55996
Published:August 05, 2026
Updated:September 01, 2026
A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate any hostname presented via Server Name Indication (SNI) in incoming TLS requests. An unauthenticated attacker with network access within the affected cluster could send a large number of TLS requests with distinct hostnames, causing the serving certificate to accumulate an unbounded number of Subject Alternative Names (SANs). Eventually, the certificate grows large enough that TLS handshakes fail with an excessive message size error, causing a denial of service on the affected listeners.
Affected Packages
https://github.com/rancher/rancher.git (GITHUB):
Affected version(s) >=v2.11.0 <v2.11.16
Fix Suggestion:
Update to version v2.11.16
https://github.com/rancher/rancher.git (GITHUB):
Affected version(s) >=v2.12.0 <v2.12.12
Fix Suggestion:
Update to version v2.12.12
https://github.com/rancher/rancher.git (GITHUB):
Affected version(s) >=v2.13.0 <v2.13.8
Fix Suggestion:
Update to version v2.13.8
https://github.com/rancher/rancher.git (GITHUB):
Affected version(s) >=v2.14.0 <v2.14.4
Fix Suggestion:
Update to version v2.14.4
github.com/rancher/rancher (GO):
Affected version(s) >=v0.0.0-20250731022323-8815e66bf2e4 <v0.0.0-20260730195259-3bc84195ee88
Fix Suggestion:
Update to version v0.0.0-20260730195259-3bc84195ee88
github.com/rancher/rancher (GO):
Affected version(s) >=v0.0.0-20260326190150-19d8a9c03fde <v0.0.0-20260730195249-79b003279fec
Fix Suggestion:
Update to version v0.0.0-20260730195249-79b003279fec
github.com/rancher/rancher (GO):
Affected version(s) >=v0.0.0-20250331174853-4b8ab8c48d68 <v0.0.0-20260730195307-e6c19548eded
Fix Suggestion:
Update to version v0.0.0-20260730195307-e6c19548eded
github.com/rancher/rancher (GO):
Affected version(s) >=v0.0.0-20251125015639-f94ac947f75e <v0.0.0-20260730195254-853a0e93a1ca
Fix Suggestion:
Update to version v0.0.0-20260730195254-853a0e93a1ca
Do you need more information?
Contact Us
CVSS v4
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
NONE
Vulnerable System Availability
LOW
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
4.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW
Weakness Type (CWE)
Allocation of Resources Without Limits or Throttling
EPSS
Base Score:
0.15