CVE-2025-54468: Suse Rancher

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or sensitive information e.g. email addresses.

Affected products

  • Suse Rancher: from 2.12.0, before 2.12.2 (fixed in 2.12.2); from 2.11.0, before 2.11.6 (fixed in 2.11.6); from 2.10.0, before 2.10.10 (fixed in 2.10.10); from 2.9.0, before 2.9.12 (fixed in 2.9.12)

Published 2025-10-02. Last modified 2026-06-17.