CVE-2026-55996
Last modified
CVE-2026-55996 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate any hostname presented via Server Name Indication (SNI) in incoming TLS requests. An unauthenticated attacker with network access within the affected cluster could send a large number of TLS requests with distinct hostnames, causing the serving certificate to accumulate an unbounded number of Subject Alternative Names (SANs). Eventually, the certificate grows large enough that TLS handshakes fail with an excessive message size error, causing a denial of service on the affected listeners.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| SUSE | Rancher | >= 2.11.0, < 2.11.16; >= 2.12.0, < 2.12.12; >= 2.13.0, < 2.13.8; >= 2.14.0, < 2.14.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-55996?
How severe is CVE-2026-55996?
How do I fix CVE-2026-55996?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5599A user with API access and "manage users" permission in any …7.3
- CVE-2026-55990In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when…5.9
- CVE-2026-55991In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a r…5.9
- CVE-2026-55993Improper Input Validation, Exposure of Sensitive Information…7.5
- CVE-2026-55994Improper Input Validation, Exposure of Sensitive Information…7.5
- CVE-2026-55995A Double Free vulnerability in open-iscsi allows an unauthen…8.7
- CVE-2026-55997Rancher issues long-lived registration tokens to authenticat…8.8
- CVE-2026-55998The endpoint /v3/import/{token}_{clusterId}.yaml retrieves t…5.3
- CVE-2026-55999Local attackers with a X connection able to provide PCX font…7.8
- CVE-2026-5600A new API endpoint introduced in pretix 2025 that is suppose…4.3
- CVE-2026-56000Local attackers with a X connection able to provide GLX comm…7.8
- CVE-2026-56001A heap buffer overflow in BitmapScaleBitmaps in libXfont2 be…8.8
Are you affected by CVE-2026-55996?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
