CVE-2026-103754
- EPSS 0.34%
- Veröffentlicht 01.10.2026 11:57:07
- Zuletzt bearbeitet 01.10.2026 18:17:12
A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating t...
CVE-2026-84721
- EPSS 0.17%
- Veröffentlicht 23.09.2026 19:40:38
- Zuletzt bearbeitet 24.09.2026 16:17:12
A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the SMTP client w...
CVE-2026-71464
- EPSS 0.21%
- Veröffentlicht 23.09.2026 18:29:02
- Zuletzt bearbeitet 24.09.2026 14:51:56
LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers. Schedule and WFJT Node accept --upload-pack=/bin/id as scm_branc...
CVE-2026-79705
- EPSS 0.25%
- Veröffentlicht 15.09.2026 16:23:26
- Zuletzt bearbeitet 02.10.2026 15:17:10
A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Bu...
CVE-2026-84185
- EPSS 0.09%
- Veröffentlicht 03.09.2026 20:46:40
- Zuletzt bearbeitet 08.09.2026 19:08:15
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error...
CVE-2026-44192
- EPSS 0.2%
- Veröffentlicht 22.07.2026 12:06:48
- Zuletzt bearbeitet 22.07.2026 16:23:35
A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the serve...
CVE-2026-44190
- EPSS 0.75%
- Veröffentlicht 22.07.2026 12:06:42
- Zuletzt bearbeitet 23.07.2026 14:17:14
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activati...
CVE-2026-16493
- EPSS 0.32%
- Veröffentlicht 21.07.2026 17:26:14
- Zuletzt bearbeitet 04.09.2026 03:17:41
A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections...
CVE-2026-12726
- EPSS 0.33%
- Veröffentlicht 19.06.2026 18:49:55
- Zuletzt bearbeitet 22.06.2026 18:33:17
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points to a trusted GitHub API endpoin...
CVE-2025-3576
- EPSS 0.33%
- Veröffentlicht 15.04.2025 05:55:26
- Zuletzt bearbeitet 01.09.2026 12:17:19
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 colli...