GHSA-4h45-jpvh-6p5j

Suggest an improvement
Source
https://github.com/advisories/GHSA-4h45-jpvh-6p5j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4h45-jpvh-6p5j/GHSA-4h45-jpvh-6p5j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4h45-jpvh-6p5j
Aliases
Published
2025-08-29T15:38:23Z
Modified
2025-09-08T14:59:25Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
Rancher affected by unauthenticated Denial of Service
Details

Impact

A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated) and authenticated API endpoints. This allows a malicious user to exploit this by sending excessively large payloads, which are fully loaded into memory during processing. This could result in:

  • Denial of Service (DoS): The server process may crash or become unresponsive when memory consumption exceeds available resources.
  • Unauthenticated and authenticated exploitation: While the issue was initially observed in unauthenticated /v3-public/* endpoints, the absence of request body size limits also affected several authenticated APIs, broadening the potential attack surface. It's worth noting that other areas in Rancher do implement safeguards: requests proxied to Kubernetes APIs are subject to built-in size limits enforced by the Kubernetes API server itself, and Norman-based endpoints parse input with predefined size caps. However, the absence of similar protections in other Rancher APIs increased the risk of denial-of-service (DoS) scenarios in certain contexts.

By sending large binary or text payloads to vulnerable endpoints, a malicious actor could disrupt Rancher’s availability, impacting both administrative and user operations across managed clusters.

Please consult the associated MITRE ATT&CK - Technique - Network Denial of Service for further information about this category of attack.

Patches

This vulnerability is addressed by adding a default limit of 1MiB and a setting in case this value needs to be increased.

Patched versions of Rancher include releases v2.12.1, v2.11.5, v2.10.9 and v2.9.12.

Workarounds

If you can't upgrade to a fixed version, please make sure that you are manually setting the request body size limits. For example, using nginx-ingress controller and only allowing requests via the ingress. For reference on how to configure the limit manually, please consult the Knowledge Base.

References

If you have any questions or comments about this advisory:

Database specific
{
    "cwe_ids":  [
        "CWE-770"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-08-29T15:38:23Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Go
github.com/rancher/rancher

Package

Name
github.com/rancher/rancher
View open source insights on deps.dev
Purl
pkg:golang/github.com/rancher/rancher

Affected ranges

Type
SEMVER
Events
Introduced
2.12.0
Fixed
2.12.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4h45-jpvh-6p5j/GHSA-4h45-jpvh-6p5j.json"
github.com/rancher/rancher

Package

Name
github.com/rancher/rancher
View open source insights on deps.dev
Purl
pkg:golang/github.com/rancher/rancher

Affected ranges

Type
SEMVER
Events
Introduced
2.11.0
Fixed
2.11.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4h45-jpvh-6p5j/GHSA-4h45-jpvh-6p5j.json"
github.com/rancher/rancher

Package

Name
github.com/rancher/rancher
View open source insights on deps.dev
Purl
pkg:golang/github.com/rancher/rancher

Affected ranges

Type
SEMVER
Events
Introduced
2.10.0
Fixed
2.10.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4h45-jpvh-6p5j/GHSA-4h45-jpvh-6p5j.json"
github.com/rancher/rancher

Package

Name
github.com/rancher/rancher
View open source insights on deps.dev
Purl
pkg:golang/github.com/rancher/rancher

Affected ranges

Type
SEMVER
Events
Introduced
2.9.0
Fixed
2.9.11

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4h45-jpvh-6p5j/GHSA-4h45-jpvh-6p5j.json"
github.com/rancher/rancher

Package

Name
github.com/rancher/rancher
View open source insights on deps.dev
Purl
pkg:golang/github.com/rancher/rancher

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20250813072957-aee95d4e2a41

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4h45-jpvh-6p5j/GHSA-4h45-jpvh-6p5j.json"