CVE-2026-19730
- EPSS 0.11%
- Veröffentlicht 13.08.2026 18:17:25
- Zuletzt bearbeitet 01.10.2026 18:17:17
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS config...
CVE-2026-12383
- EPSS 0.16%
- Veröffentlicht 27.07.2026 19:17:14
- Zuletzt bearbeitet 04.08.2026 21:16:34
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentic...
CVE-2026-44191
- EPSS 0.82%
- Veröffentlicht 22.07.2026 12:11:29
- Zuletzt bearbeitet 22.07.2026 19:17:03
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts se...
CVE-2026-44189
- EPSS 0.95%
- Veröffentlicht 22.07.2026 12:06:36
- Zuletzt bearbeitet 22.07.2026 16:23:35
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the...
CVE-2026-16544
- EPSS 0.39%
- Veröffentlicht 22.07.2026 11:15:53
- Zuletzt bearbeitet 22.07.2026 18:16:59
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_upda...
CVE-2026-11807
- EPSS 0.42%
- Veröffentlicht 23.06.2026 19:40:33
- Zuletzt bearbeitet 16.07.2026 12:17:00
A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged mess...
CVE-2026-12398
- EPSS 0.89%
- Veröffentlicht 16.06.2026 14:52:06
- Zuletzt bearbeitet 29.06.2026 18:16:36
A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. A...
CVE-2026-44188
- EPSS 0.28%
- Veröffentlicht 15.06.2026 08:36:06
- Zuletzt bearbeitet 20.08.2026 16:17:23
A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authoriz...
CVE-2026-44495
- EPSS 0.78%
- Veröffentlicht 11.06.2026 15:33:12
- Zuletzt bearbeitet 11.09.2026 13:18:08
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...
CVE-2026-46625
- EPSS 0.67%
- Veröffentlicht 10.06.2026 21:18:05
- Zuletzt bearbeitet 09.09.2026 13:20:18
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON objec...