๐Ÿ” CVE Alert

CVE-2026-55996

MEDIUM 4.3

Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agent

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate any hostname presented via Server Name Indication (SNI) in incoming TLS requests. An unauthenticated attacker with network access within the affected cluster could send a large number of TLS requests with distinct hostnames, causing the serving certificate to accumulate an unbounded number of Subject Alternative Names (SANs). Eventually, the certificate grows large enough that TLS handshakes fail with an excessive message size error, causing a denial of service on the affected listeners.

Vendor suse
Product rancher
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for suse rancher

Be the first to know when new medium vulnerabilities affecting suse rancher are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

SUSE / Rancher
2.11.0 < 2.11.16 2.12.0 < 2.12.12 2.13.0 < 2.13.8 2.14.0 < 2.14.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rancher/rancher/security/advisories/GHSA-9jxv-832x-45q9 bugzilla.suse.com: https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55996