github.com/rancher/fleet
Deploy workloads from Git to large fleets of Kubernetes clusters
Activity
- Latest release
- 6d ago
- Total releases
- 72
- Cadence
- ~5 days
- Last 12 months
- 41
Reach
- Stars
- 1.7k
Details
- First release
- Apr 15, 2020
| Version | Released | |
|---|---|---|
v0.16.2-rc.1
pre
|
v0.16.2-rc.1
pre
Dependencies (63)
+ 55 more |
|
v0.17.0-alpha.3
pre
|
v0.17.0-alpha.3
pre
Dependencies (63)
+ 55 more |
|
v0.17.0-alpha.2
pre
|
v0.17.0-alpha.2
pre
Dependencies (63)
+ 55 more |
|
v0.17.0-alpha.1
pre
|
v0.17.0-alpha.1
pre
Dependencies (62)
+ 54 more |
|
v0.16.1
patch
|
v0.16.1
patch
Dependencies (62)
+ 54 more |
|
v0.16.1-rc.2
pre
|
v0.16.1-rc.2
pre
Dependencies (62)
+ 54 more |
|
v0.16.1-rc.1
pre
|
v0.16.1-rc.1
pre
Dependencies (62)
+ 54 more |
|
v0.16.1-beta.2
pre
|
v0.16.1-beta.2
pre
Dependencies (61)
+ 53 more |
|
v0.16.1-beta.1
pre
|
v0.16.1-beta.1
pre
Dependencies (61)
+ 53 more |
|
v0.13.14-rc.2
pre
|
v0.13.14-rc.2
pre
Dependencies (58)
+ 50 more |
|
v0.16.0-rc.5
pre
|
v0.16.0-rc.5
pre
Dependencies (61)
+ 53 more |
|
v0.16.0
minor
|
v0.16.0
minor
Dependencies (61)
+ 53 more |
|
v0.16.0-rc.4
pre
|
v0.16.0-rc.4
pre
Dependencies (61)
+ 53 more |
|
v0.16.0-rc.3
pre
|
v0.16.0-rc.3
pre
Dependencies (61)
+ 53 more |
|
v0.12.18-rc.1
pre
|
v0.12.18-rc.1
pre
Dependencies (61)
+ 53 more |
|
v0.16.0-rc.2
pre
|
v0.16.0-rc.2
pre
Dependencies (61)
+ 53 more |
|
v0.12.17
patch
|
v0.12.17
patch
Dependencies (61)
+ 53 more |
|
v0.16.0-rc.1
pre
|
v0.16.0-rc.1
pre
Dependencies (61)
+ 53 more |
|
v0.16.0-beta.2
pre
|
v0.16.0-beta.2
pre
Dependencies (59)
+ 51 more |
|
v0.16.0-beta.1
pre
|
v0.16.0-beta.1
pre
Dependencies (59)
+ 51 more |
|
v0.16.0-alpha.11
pre
|
v0.16.0-alpha.11
pre
Dependencies (59)
+ 51 more |
|
v0.16.0-alpha.10
pre
|
v0.16.0-alpha.10
pre
Dependencies (59)
+ 51 more |
|
v0.16.0-alpha.9
pre
|
v0.16.0-alpha.9
pre
Dependencies (58)
+ 50 more |
|
v0.16.0-alpha.8
pre
|
v0.16.0-alpha.8
pre
Dependencies (58)
+ 50 more |
|
v0.16.0-alpha.7
pre
|
v0.16.0-alpha.7
pre
Dependencies (58)
+ 50 more |
|
v0.16.0-alpha.6
pre
|
v0.16.0-alpha.6
pre
Dependencies (57)
+ 49 more |
|
v0.16.0-alpha.5
pre
|
v0.16.0-alpha.5
pre
Dependencies (57)
+ 49 more |
|
v0.16.0-alpha.4
pre
|
v0.16.0-alpha.4
pre
Dependencies (57)
+ 49 more |
|
v0.16.0-alpha.3
pre
|
v0.16.0-alpha.3
pre
Dependencies (57)
+ 49 more |
|
v0.16.0-alpha.2
pre
|
v0.16.0-alpha.2
pre
Dependencies (57)
+ 49 more |
|
v0.14.5-beta.2
pre
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.14.5-beta.2
pre
Dependencies (57)
+ 49 more |
|
v0.13.9-rc.4
pre
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.13.9-rc.4
pre
Dependencies (56)
+ 48 more |
|
v0.14.3
minor
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.14.3
minor
Dependencies (61)
+ 53 more |
|
v0.13.8-rc.1
pre
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.13.8-rc.1
pre
Dependencies (59)
+ 51 more |
|
v0.12.12-rc.1
pre
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.12.12-rc.1
pre
Dependencies (62)
+ 54 more |
|
v0.12.11-rc.2
pre
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.12.11-rc.2
pre
Dependencies (62)
+ 54 more |
|
v0.14.2-beta.1
pre
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.14.2-beta.1
pre
Dependencies (61)
+ 53 more |
|
v0.13.6-hotfix-05d1.2
pre
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.13.6-hotfix-05d1.2
pre
Dependencies (59)
+ 51 more |
|
v0.13.7-alpha.1
pre
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.13.7-alpha.1
pre
Dependencies (59)
+ 51 more |
|
v0.12.9
patch
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.12.9
patch
Dependencies (62)
+ 54 more |
|
v0.12.9-rc.1
pre
5 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.12.9-rc.1
pre
Dependencies (62)
+ 54 more |
|
v0.14.0-experiment-98d0.7
pre
|
v0.14.0-experiment-98d0.7
pre
Dependencies (59)
+ 51 more |
|
v0.14.0-experiment-98d0.6
pre
|
v0.14.0-experiment-98d0.6
pre
Dependencies (59)
+ 51 more |
|
v0.11.8
patch
2 CVEs
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-52284
GO-2025-3927
GHSA-6h9x-9j5v-7w9h
Sep 08, 2025
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Fixed in
0.11.10
0.12.6
0.13.1-0.20250806151509-088bcbea7edb
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.11.8
patch
Dependencies (59)
+ 51 more |
|
v0.12.3-rc.1
pre
6 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-52284
GO-2025-3927
GHSA-6h9x-9j5v-7w9h
Sep 08, 2025
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Fixed in
0.11.10
0.12.6
0.13.1-0.20250806151509-088bcbea7edb
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.3-rc.1
pre
Dependencies (61)
+ 53 more |
|
v0.11.7
minor
2 CVEs
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-52284
GO-2025-3927
GHSA-6h9x-9j5v-7w9h
Sep 08, 2025
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Fixed in
0.11.10
0.12.6
0.13.1-0.20250806151509-088bcbea7edb
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.11.7
minor
Dependencies (59)
+ 51 more |
|
v0.12.1
minor
7 CVEs
CVE-2026-44937
GO-2026-5874
GHSA-jmf4-m7j9-g72r
Jul 07, 2026
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44938
GO-2026-5871
GHSA-864g-863m-vcvq
Jul 07, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44935
GO-2026-5877
GHSA-xr65-5cpm-g36x
Jul 07, 2026
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44936
GO-2026-5873
GHSA-hx4v-cxpf-vh8m
Jul 07, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet Fixed in
0.12.15
0.13.11
0.14.6
0.15.2
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-52284
GO-2025-3927
GHSA-6h9x-9j5v-7w9h
Sep 08, 2025
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Fixed in
0.11.10
0.12.6
0.13.1-0.20250806151509-088bcbea7edb
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23390
GO-2025-3649
GHSA-xgpc-q899-67p8
May 05, 2025
Fleet doesn’t validate a server’s certificate when connecting through SSH in github.com/rancher/fleet Fleet doesn’t validate a server’s certificate when connecting through SSH in github.com/rancher/fleet Fixed in
0.10.12
0.11.7
0.12.2
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.12.1
minor
Dependencies (61)
+ 53 more |
|
v0.12.0-rc.1
pre
|
v0.12.0-rc.1
pre
Dependencies (61)
+ 53 more |
|
v0.11.4-hotfix-ac6b.1
pre
3 CVEs
CVE-2026-41050
GO-2026-5207
GHSA-765j-qfrp-hm3j
Jun 25, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet Fleet: Helm impersonation bypass of Fixed in
0.11.13
0.12.14
0.13.10
0.14.5
0.15.1
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-52284
GO-2025-3927
GHSA-6h9x-9j5v-7w9h
Sep 08, 2025
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet Fixed in
0.11.10
0.12.6
0.13.1-0.20250806151509-088bcbea7edb
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23390
GO-2025-3649
GHSA-xgpc-q899-67p8
May 05, 2025
Fleet doesn’t validate a server’s certificate when connecting through SSH in github.com/rancher/fleet Fleet doesn’t validate a server’s certificate when connecting through SSH in github.com/rancher/fleet Fixed in
0.10.12
0.11.7
0.12.2
References
Updated Mar 03, 2026 · Source: OSV.dev |
v0.11.4-hotfix-ac6b.1
pre
Dependencies (59)
+ 51 more |
|
v0.12.0-alpha.7
pre
|
v0.12.0-alpha.7
pre
Dependencies (61)
+ 53 more |