github.com/rancher/rke2
Activity
- Latest release
- 6y ago
- Total releases
- 7
- Cadence
- ~3 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- May 07, 2020
| Version | Released | |
|---|---|---|
v0.0.1-alpha.7
pre
2 CVEs
GO-2024-3222
GHSA-x7xj-jvwp-97rv
Oct 28, 2024
RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2 RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/rancher/rke2 from v1.27.0 before v1.27.15, from v1.28.0 before v1.28.11, from v1.29.0 before v1.29.6, from v1.30.0 before v1.30.2. References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2023-32186
GHSA-p45j-vfv5-wprq
Sep 11, 2023
RKE2 supervisor port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn issue was found in RKE2 where an attacker with network access to RKE2 servers' supervisor port (TCP 9345) can force the TLS server to add entries to the certificate's Subject Alternative Name (SAN) list, through a stuffing attack, until the certificate grows so large that it exceeds the maximum size allowed by TLS client implementations. OpenSSL for example will raise an Affected servers will continue to operate, but clients (server or agent nodes) will fail to establish new connections when joining or rejoining the cluster, thus leading to a denial of service (DoS) attack. RemediationUpgrade to a fixed release:
If you are using RKE2 1.27 or earlier, you must also add the parameter Note that this flag changes the behavior of RKE2's supervisor listener. You should ensure that you configure MitigationIf you cannot upgrade to a fixed release, the certificate can be "frozen" by running the following command against the cluster:
⚠️ IMPORTANT CAUTION: Note that this mitigation will prevent the certificate from adding new SAN entries when servers join the cluster, and automatically renewing itself when it is about to expire. If you do this, you should delete the annotation when adding new servers to the cluster, or when the certificate is within 90 days of expiring, so that it can be updated. Once that is done, you can freeze it again. Affected certificates can be reset by performing the following steps:
BackgroundThe RKE2 supervisor listens on port TCP 9345 and uses the The library allows the embedding application to configure a callback that is used to filter addresses requested by clients; but this was not previously implemented in RKE2. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References Updated May 04, 2026 · Source: OSV.dev |
v0.0.1-alpha.7
pre
Dependencies (12)
+ 4 more |
|
v0.0.1-alpha.6
pre
2 CVEs
GO-2024-3222
GHSA-x7xj-jvwp-97rv
Oct 28, 2024
RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2 RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/rancher/rke2 from v1.27.0 before v1.27.15, from v1.28.0 before v1.28.11, from v1.29.0 before v1.29.6, from v1.30.0 before v1.30.2. References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2023-32186
GHSA-p45j-vfv5-wprq
Sep 11, 2023
RKE2 supervisor port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn issue was found in RKE2 where an attacker with network access to RKE2 servers' supervisor port (TCP 9345) can force the TLS server to add entries to the certificate's Subject Alternative Name (SAN) list, through a stuffing attack, until the certificate grows so large that it exceeds the maximum size allowed by TLS client implementations. OpenSSL for example will raise an Affected servers will continue to operate, but clients (server or agent nodes) will fail to establish new connections when joining or rejoining the cluster, thus leading to a denial of service (DoS) attack. RemediationUpgrade to a fixed release:
If you are using RKE2 1.27 or earlier, you must also add the parameter Note that this flag changes the behavior of RKE2's supervisor listener. You should ensure that you configure MitigationIf you cannot upgrade to a fixed release, the certificate can be "frozen" by running the following command against the cluster:
⚠️ IMPORTANT CAUTION: Note that this mitigation will prevent the certificate from adding new SAN entries when servers join the cluster, and automatically renewing itself when it is about to expire. If you do this, you should delete the annotation when adding new servers to the cluster, or when the certificate is within 90 days of expiring, so that it can be updated. Once that is done, you can freeze it again. Affected certificates can be reset by performing the following steps:
BackgroundThe RKE2 supervisor listens on port TCP 9345 and uses the The library allows the embedding application to configure a callback that is used to filter addresses requested by clients; but this was not previously implemented in RKE2. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References Updated May 04, 2026 · Source: OSV.dev |
v0.0.1-alpha.6
pre
Dependencies (12)
+ 4 more |
|
v0.0.1-alpha.5
pre
2 CVEs
GO-2024-3222
GHSA-x7xj-jvwp-97rv
Oct 28, 2024
RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2 RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/rancher/rke2 from v1.27.0 before v1.27.15, from v1.28.0 before v1.28.11, from v1.29.0 before v1.29.6, from v1.30.0 before v1.30.2. References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2023-32186
GHSA-p45j-vfv5-wprq
Sep 11, 2023
RKE2 supervisor port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn issue was found in RKE2 where an attacker with network access to RKE2 servers' supervisor port (TCP 9345) can force the TLS server to add entries to the certificate's Subject Alternative Name (SAN) list, through a stuffing attack, until the certificate grows so large that it exceeds the maximum size allowed by TLS client implementations. OpenSSL for example will raise an Affected servers will continue to operate, but clients (server or agent nodes) will fail to establish new connections when joining or rejoining the cluster, thus leading to a denial of service (DoS) attack. RemediationUpgrade to a fixed release:
If you are using RKE2 1.27 or earlier, you must also add the parameter Note that this flag changes the behavior of RKE2's supervisor listener. You should ensure that you configure MitigationIf you cannot upgrade to a fixed release, the certificate can be "frozen" by running the following command against the cluster:
⚠️ IMPORTANT CAUTION: Note that this mitigation will prevent the certificate from adding new SAN entries when servers join the cluster, and automatically renewing itself when it is about to expire. If you do this, you should delete the annotation when adding new servers to the cluster, or when the certificate is within 90 days of expiring, so that it can be updated. Once that is done, you can freeze it again. Affected certificates can be reset by performing the following steps:
BackgroundThe RKE2 supervisor listens on port TCP 9345 and uses the The library allows the embedding application to configure a callback that is used to filter addresses requested by clients; but this was not previously implemented in RKE2. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References Updated May 04, 2026 · Source: OSV.dev |
v0.0.1-alpha.5
pre
Dependencies (12)
+ 4 more |
|
v0.0.1-alpha.4
pre
2 CVEs
GO-2024-3222
GHSA-x7xj-jvwp-97rv
Oct 28, 2024
RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2 RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/rancher/rke2 from v1.27.0 before v1.27.15, from v1.28.0 before v1.28.11, from v1.29.0 before v1.29.6, from v1.30.0 before v1.30.2. References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2023-32186
GHSA-p45j-vfv5-wprq
Sep 11, 2023
RKE2 supervisor port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn issue was found in RKE2 where an attacker with network access to RKE2 servers' supervisor port (TCP 9345) can force the TLS server to add entries to the certificate's Subject Alternative Name (SAN) list, through a stuffing attack, until the certificate grows so large that it exceeds the maximum size allowed by TLS client implementations. OpenSSL for example will raise an Affected servers will continue to operate, but clients (server or agent nodes) will fail to establish new connections when joining or rejoining the cluster, thus leading to a denial of service (DoS) attack. RemediationUpgrade to a fixed release:
If you are using RKE2 1.27 or earlier, you must also add the parameter Note that this flag changes the behavior of RKE2's supervisor listener. You should ensure that you configure MitigationIf you cannot upgrade to a fixed release, the certificate can be "frozen" by running the following command against the cluster:
⚠️ IMPORTANT CAUTION: Note that this mitigation will prevent the certificate from adding new SAN entries when servers join the cluster, and automatically renewing itself when it is about to expire. If you do this, you should delete the annotation when adding new servers to the cluster, or when the certificate is within 90 days of expiring, so that it can be updated. Once that is done, you can freeze it again. Affected certificates can be reset by performing the following steps:
BackgroundThe RKE2 supervisor listens on port TCP 9345 and uses the The library allows the embedding application to configure a callback that is used to filter addresses requested by clients; but this was not previously implemented in RKE2. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References Updated May 04, 2026 · Source: OSV.dev |
v0.0.1-alpha.4
pre
Dependencies (12)
+ 4 more |
|
v0.0.1-alpha.3
pre
2 CVEs
GO-2024-3222
GHSA-x7xj-jvwp-97rv
Oct 28, 2024
RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2 RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/rancher/rke2 from v1.27.0 before v1.27.15, from v1.28.0 before v1.28.11, from v1.29.0 before v1.29.6, from v1.30.0 before v1.30.2. References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2023-32186
GHSA-p45j-vfv5-wprq
Sep 11, 2023
RKE2 supervisor port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn issue was found in RKE2 where an attacker with network access to RKE2 servers' supervisor port (TCP 9345) can force the TLS server to add entries to the certificate's Subject Alternative Name (SAN) list, through a stuffing attack, until the certificate grows so large that it exceeds the maximum size allowed by TLS client implementations. OpenSSL for example will raise an Affected servers will continue to operate, but clients (server or agent nodes) will fail to establish new connections when joining or rejoining the cluster, thus leading to a denial of service (DoS) attack. RemediationUpgrade to a fixed release:
If you are using RKE2 1.27 or earlier, you must also add the parameter Note that this flag changes the behavior of RKE2's supervisor listener. You should ensure that you configure MitigationIf you cannot upgrade to a fixed release, the certificate can be "frozen" by running the following command against the cluster:
⚠️ IMPORTANT CAUTION: Note that this mitigation will prevent the certificate from adding new SAN entries when servers join the cluster, and automatically renewing itself when it is about to expire. If you do this, you should delete the annotation when adding new servers to the cluster, or when the certificate is within 90 days of expiring, so that it can be updated. Once that is done, you can freeze it again. Affected certificates can be reset by performing the following steps:
BackgroundThe RKE2 supervisor listens on port TCP 9345 and uses the The library allows the embedding application to configure a callback that is used to filter addresses requested by clients; but this was not previously implemented in RKE2. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References Updated May 04, 2026 · Source: OSV.dev |
v0.0.1-alpha.3
pre
Dependencies (12)
+ 4 more |
|
v0.0.1-alpha.2
pre
2 CVEs
GO-2024-3222
GHSA-x7xj-jvwp-97rv
Oct 28, 2024
RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2 RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/rancher/rke2 from v1.27.0 before v1.27.15, from v1.28.0 before v1.28.11, from v1.29.0 before v1.29.6, from v1.30.0 before v1.30.2. References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2023-32186
GHSA-p45j-vfv5-wprq
Sep 11, 2023
RKE2 supervisor port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn issue was found in RKE2 where an attacker with network access to RKE2 servers' supervisor port (TCP 9345) can force the TLS server to add entries to the certificate's Subject Alternative Name (SAN) list, through a stuffing attack, until the certificate grows so large that it exceeds the maximum size allowed by TLS client implementations. OpenSSL for example will raise an Affected servers will continue to operate, but clients (server or agent nodes) will fail to establish new connections when joining or rejoining the cluster, thus leading to a denial of service (DoS) attack. RemediationUpgrade to a fixed release:
If you are using RKE2 1.27 or earlier, you must also add the parameter Note that this flag changes the behavior of RKE2's supervisor listener. You should ensure that you configure MitigationIf you cannot upgrade to a fixed release, the certificate can be "frozen" by running the following command against the cluster:
⚠️ IMPORTANT CAUTION: Note that this mitigation will prevent the certificate from adding new SAN entries when servers join the cluster, and automatically renewing itself when it is about to expire. If you do this, you should delete the annotation when adding new servers to the cluster, or when the certificate is within 90 days of expiring, so that it can be updated. Once that is done, you can freeze it again. Affected certificates can be reset by performing the following steps:
BackgroundThe RKE2 supervisor listens on port TCP 9345 and uses the The library allows the embedding application to configure a callback that is used to filter addresses requested by clients; but this was not previously implemented in RKE2. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References Updated May 04, 2026 · Source: OSV.dev |
v0.0.1-alpha.2
pre
Dependencies (12)
+ 4 more |
|
v0.0.1-alpha.1
pre
2 CVEs
GO-2024-3222
GHSA-x7xj-jvwp-97rv
Oct 28, 2024
RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2 RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rke2. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/rancher/rke2 from v1.27.0 before v1.27.15, from v1.28.0 before v1.28.11, from v1.29.0 before v1.29.6, from v1.30.0 before v1.30.2. References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2023-32186
GHSA-p45j-vfv5-wprq
Sep 11, 2023
RKE2 supervisor port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attack
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactAn issue was found in RKE2 where an attacker with network access to RKE2 servers' supervisor port (TCP 9345) can force the TLS server to add entries to the certificate's Subject Alternative Name (SAN) list, through a stuffing attack, until the certificate grows so large that it exceeds the maximum size allowed by TLS client implementations. OpenSSL for example will raise an Affected servers will continue to operate, but clients (server or agent nodes) will fail to establish new connections when joining or rejoining the cluster, thus leading to a denial of service (DoS) attack. RemediationUpgrade to a fixed release:
If you are using RKE2 1.27 or earlier, you must also add the parameter Note that this flag changes the behavior of RKE2's supervisor listener. You should ensure that you configure MitigationIf you cannot upgrade to a fixed release, the certificate can be "frozen" by running the following command against the cluster:
⚠️ IMPORTANT CAUTION: Note that this mitigation will prevent the certificate from adding new SAN entries when servers join the cluster, and automatically renewing itself when it is about to expire. If you do this, you should delete the annotation when adding new servers to the cluster, or when the certificate is within 90 days of expiring, so that it can be updated. Once that is done, you can freeze it again. Affected certificates can be reset by performing the following steps:
BackgroundThe RKE2 supervisor listens on port TCP 9345 and uses the The library allows the embedding application to configure a callback that is used to filter addresses requested by clients; but this was not previously implemented in RKE2. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References Updated May 04, 2026 · Source: OSV.dev |
v0.0.1-alpha.1
pre
Dependencies (12)
+ 4 more |