Affected by GO-2025-3649
and 6 other vulnerabilities
GO-2025-3649: Fleet doesn’t validate a server’s certificate when connecting through SSH in github.com/rancher/fleet
GO-2025-3927: Rancher Fleet Helm Values are stored inside BundleDeployment in plain text in github.com/rancher/fleet
GO-2026-5207: Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering in github.com/rancher/fleet
GO-2026-5871: Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet
GO-2026-5873: Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet
GO-2026-5874: Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet
GO-2026-5877: Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet
SystemRegistrationNamespace generates the name of the system registration
namespace from the configured system namespace, e.g.:
cattle-fleet-system -> cattle-fleet-clusters-system