Affected by GO-2026-5871
and 3 other vulnerabilities
GO-2026-5871: Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent in github.com/rancher/fleet
GO-2026-5873: Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml in github.com/rancher/fleet
GO-2026-5874: Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components in github.com/rancher/fleet
GO-2026-5877: Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet