CVE-2024-58259: Suse Rancher
High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated) and authenticated API endpoints. This allows a malicious user to exploit this by sending excessively large payloads, which are fully loaded into memory during processing, leading to Denial of Service (DoS).
Affected products
- Suse Rancher: from 2.12.0, before 2.12.1 (fixed in 2.12.1); from 2.11.0, before 2.11.5 (fixed in 2.11.5); from 2.10.0, before 2.10.9 (fixed in 2.10.9); from 2.9.0, before 2.9.11 (fixed in 2.9.11); before 0.0.0-20250813072957-aee95d4e2a41 (fixed in 0.0.0-20250813072957-aee95d4e2a41)
Published 2025-09-02. Last modified 2026-06-17.