Information Exposure Affecting github.com/rancher/rancher/pkg/api/norman/customization/clusterregistrationtokens package, versions >=2.11.0-alpha1 <2.11.16-alpha2>=2.12.0-alpha1 <2.12.12-alpha2>=2.13.0-alpha1 <2.13.8-alpha2>=2.14.0-alpha1 <2.14.4-alpha2


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.34% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMRANCHERRANCHERPKGAPINORMANCUSTOMIZATIONCLUSTERREGISTRATIONTOKENS-18600484
  • published9 Aug 2026
  • disclosed5 Aug 2026
  • creditUnknown

Introduced: 5 Aug 2026

CVE-2026-55998  (opens in a new tab)
CWE-204  (opens in a new tab)

How to fix?

Upgrade github.com/rancher/rancher/pkg/api/norman/customization/clusterregistrationtokens to version 2.11.16-alpha2, 2.12.12-alpha2, 2.13.8-alpha2, 2.14.4-alpha2 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure in pkg/api/norman/customization/clusterregistrationtokens/import.go is vulnerable to an unauthenticated cluster-existence oracle through the /v3/import/{token}_{clusterId}.yaml import endpoint. An attacker can enumerate valid cluster IDs and infer whether a cluster has private registry secrets configured by sending import requests with guessed cluster IDs and observing the different responses. When the handler looks up the cluster before checking the token, a nonexistent cluster returns HTTP 200, while a valid cluster that reaches the private-registry code path can trigger a HTTP 502 Bad Gateway via a nil pointer dereference. This lets an unauthenticated remote attacker fingerprint cluster presence and registry configuration, exposing infrastructure details useful for follow-on attacks.

CVSS Base Scores

version 4.0
version 3.1