Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44937.json",
"cwe_ids": [
"CWE-918"
],
"cna_assigner": "suse"
}{
"extracted_events": [
{
"introduced": "0.12.0"
},
{
"fixed": "0.12.15"
},
{
"introduced": "0.13.0"
},
{
"fixed": "0.13.11"
},
{
"introduced": "0.14.0"
},
{
"fixed": "0.14.6"
},
{
"introduced": "0.15.0"
},
{
"fixed": "0.15.2"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:*"
}