At SUSE, we are deeply committed to maintaining the trust of our customers and the broader open-source community. Open collaboration, transparency, and secure product development are fundamental to our mission.
Important
Please refer to our company-wide SUSE Coordinated Vulnerability Disclosure ("CVD") Policy, for more information.
We go through all reported security issues, reviewing them with the project's maintainers and coordinating the fixes and disclosures. We credit all accepted reports from users and security researchers in our Security Advisories.
Caution
Do not test potential exploits or vulnerabilities on any system without explicit authorization from the system owner.
Warning
Reported vulnerabilities must affect a supported version of the SUSE Rancher ecosystem. Refer to SUSE Support Lifecycle for current support status.
Example of valid reports:
- XSS on Rancher Manager UI.
- Privilege escalation through Rancher Manager RBAC.
If you are unsure, check the types of issues NOT to report below.
Do NOT report the following via this channel:
- Public CVEs generated by automated scanners (e.g., Trivy, Snyk) as they are fixed as part of the development process.
- Non-security bugs or documentation improvements. Report them via issues in Rancher or documentation issues issues.
- Self-inflicted issues requiring degraded security settings, or admin-only exploitation.
Submit reports via email to psirt@suse.com. We recommend OpenPGP encrypted and signed email, please check the section below for more details.
Warning
The information below MUST be provided in order for the report to be timely and effectively analyzed.
Reports that miss the required information might be considered AI generated spam or reviewed with a lower priority.
- Product Name & Version: Affected product and version, or GitHub source code link, if the issue was observed in the source code.
- Description: Complete description of the vulnerability.
- Impact: Classification of issue type and potential impact when exploited.
- Steps to Reproduce Clear, step-by-step reproduction instructions or proof of concept (POC).
Tip
The more information you provide, the faster we will be able to reproduce the issue and address your concerns more effectively.
To ensure the integrity and confidentiality of our communications, we recommend that individuals reaching out to the SUSE Product Security team utilize openPGP encryption. Note that while message contents are protected, the email subject or the names of any attached files will be excluded from encryption.
Our official public key is available here:
pub ed25519/0xE0D1EF75DEBDFEE9 2026-09-01 [SC] [expires: 2037-09-01]
Key fingerprint = AB20 5CE3 088C 1F1B CE74 DC99 E0D1 EF75 DEBD FEE9
uid [ full ] SUSE Product Security Incident Response Team psirt@suse.com
sub cv25519/0xA4B7B686CC4152BD 2026-09-01 [E] [expires: 2037-09-01]
Key fingerprint = B13E 46DE 87EB 81D5 15E1 1909 A4B7 B686 CC41 52BD
The key is listed below in ASCII encoded form.
-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEapZ8VhYJKwYBBAHaRw8BAQdADoggNgBrXHimYH+7t5WVzBnhQmT8UPUIQQWH
pzLMaB+0PVNVU0UgUHJvZHVjdCBTZWN1cml0eSBJbmNpZGVudCBSZXNwb25zZSBU
ZWFtIDxwc2lydEBzdXNlLmNvbT6ImQQTFgoAQRYhBKsgXOMIjB8bznTcmeDR73Xe
vf7pBQJqlnxWAhsDBQkUsUK6BQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheAAAoJ
EODR73Xevf7pRkMA/0XDeysUhC66NgiF7AVno+QBkyJso2pkbQQG3su+Oi9hAQCd
yy3iScttdmFKTqQr4N7redFAJ3Esw5vtxVzMHZhpCIkCMwQQAQgAHRYhBFzzxI6z
KP0xgVwUfZLb1rIpR3voBQJqlnyMAAoJEJLb1rIpR3voRUUP/0rHbb/m47zHc834
G1CPaExiYOrtdckXNDwjno/r+2RppWy6ZxtM8KeLz+414NPxYUPNlyAvXd9pY3lW
sxQkDyJFrIJd0MDXiM8gDPyMuEB9k+yWeofJLcx6LfLvwJnFLwSSHcUWqmPcC6AI
TYVRhY6Gn9sNfJ5DnjQCxahZN55aGff2v0KiSPHrDqE59soLOQH7Vv2xuFVoWIYG
E8FZlzfIsfXJX0mBMrDxXO1+SGzDEdmcgLihhLHCcgmTCizz9S2qGLw3yaeI3NDB
xWafFrW80XGELXn+DdWP/khuU+PGfb0JcfroyR6GGNfAX5BC9O7yePGya+fZB8UD
puf93Q58Exu23KmQ00d0p2ey5t+KSFzmhk4knh6T50qEPm5Z04dwlzbnGwrn9qKS
iZuHn82Xx5B8eQ0nUN9jql1k/tjmeSXrhzfwoGhp4vCbz0AwAAglNo7pEb7j0xHF
C866ZCrQsQxVUcJCSox0HC27YZUvw2fvc57Lb+tkIxGi/AS0/Pe6lRHannqDzpwV
EW4WWIf6wE746M38q779p6PrH8Cu+aVWVCw+ZFNgv7GB/k0NeQUeliZ/xb40wKo4
zwm6X8emOI/jkQ6fF9JCw7PXf+eFsy1CbB8sKCkFDkew1g9008lWnywxtx79c+Ks
tTMW5IlYQE5wWvLmPG87Sow9wHUSiQIzBBABCAAdFiEEXPPEjrMo/TGBXBR9ktvW
silHe+gFAmqWfLMACgkQktvWsilHe+h1Eg//bHdyPYiJPkKvsHf1guYD/OwEWm32
1KlfKBKzpM1lZyyHjmNLetnytmypixiRvLuk1R4bTrn+AzwfvaJxqP1O3Ffm6Nub
npjhasBK1ehHL1KbN3ayiuOjjHEubj4ODtZd7QTjSLPNCgapL/N69lHoE6z7Hn+O
MSdy+tZdNKYmQSZdtxsLdzUsnbBItQS2X9Ow1Mwxnj2VHlmJ2WAz+RYh/npFbxc0
jBDuGg8BIAQRovOym7zP3ubIMlWEbj0uEyNdoFh7qyBp/dC7cqMVykMJHMS2ywNJ
ic20wHZNioRkvRmBIfUS2LSSoSX75y5NWunm9umLZq9bveCCANtRnWA/OrWjM9Dv
bYgn3MUP50ppD8VhWg36jqWjQ4el4J+pZR+NnaqQb5EfFqk6LfHgcbEyBjvwx9EI
AxBTLUEsMCQh65O1tA8flp7EsnPNS5Gq43ceZ/2zqSN+nT6P9USrlvoaY7DycG3H
pW0ivUcILFem3Dv+hpOiu8l4fG34Sc+5iSsMP+3C4FF3b3zaT/OZVcrYz+9Lbel+
wnttWiXAc1uY6g0BDBWfxqINMHTuqyI28kJpJwohIsAJupWiLBPJirbHxz3sCH1k
iTwKsQ9AQB6QG5kbTyI2XvMAoRS9sLJOIgj1XCQ5iPCnCqCW/5yUZXTLEE1hgDrP
4vNXGiDotSsrg1a4OARqlnxWEgorBgEEAZdVAQUBAQdAIK9oQ08e7coYwqNlcumv
kbxAtYZp/znHfF18qmaClEgDAQgHiH4EGBYKACYWIQSrIFzjCIwfG8503Jng0e91
3r3+6QUCapZ8VgIbDAUJFLFCugAKCRDg0e913r3+6UnaAQCo9GLby0CgazcDlo91
X99FhvSAKWmszQg/HXmFACe0IwD/Sv7t62yxGgGebbWdzfPbJOMdqo5ZPq8Yqzal
CNPwEwU=
=qfoM
-----END PGP PUBLIC KEY BLOCK-----
Please refer to our SUSE Coordinated Vulnerability Disclosure ("CVD") Policy, for more information about our commitments and what you can expect after reporting a vulnerability, as well as how to make an anonymous report and more.