
🚨 HIGH - Rancher Fleet webhook request forgery enables repo re-clone DoS & revision rollback (CVE-2026-44937) Rancher Fleet is vulnerable when the webhook endpoint is deployed without a configured secret, allowing unauthenticated attackers to forge webhook calls against the Fleet webhook handler in http://github.com/rancher/fleet. The root cause is improper authentication/validation of webhook requests combined with regex-based injection via unescaped webhook-supplied repository URL/path components. An attacker can exploit this by sending crafted webhook payloads to the exposed endpoint (no privileges needed if the secret is unset), forcing Fleet to repeatedly re-clone targeted Git repositories and potentially select historical revisions. Real-world impact includes management-cluster resource exhaustion/denial of service and unintended service downgrades to older, attacker-chosen states sourced from remote Git. 👉 Affected: http://github.com/rancher/fleet (webhook endpoint configured without a secret; versions prior to patched release) | Upgrade to the vendor patched version that escapes webhook-provided repo URL/path components
Post summary
The tweet announces CVE‑2026‑44937, describing a webhook forgery in Rancher Fleet that can lead to DoS and rollback, and advises upgrading to a patched release to mitigate.
