Red Hat Ansible Automation Platform 2: server-side request forgery
Medium6.4CVE-2026-79717 · Published Aug 25, 2026 · updated Aug 28, 2026
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or cloud instance metadata endpoints. A background worker fetches that URL without checking the destination, which lets the attacker probe internal services and enumerate reachable IP addresses. The HTTP client is also configured without an overall timeout, so a slow or non-responsive target can pin workers and cause a denial of service.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Ansible Automation Platform 2 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 25 | Red Hat Enterprise Linux: type confusion | Medium5.7 | No fix yet |
| Aug 25 | Red Hat Enterprise Linux: stack buffer overflow | High7.6 | No fix yet |
| Aug 25 | Red Hat file-xwd plugin: out-of-bounds read | Medium4.4 | No fix yet |
| Aug 25 | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing | Medium5.3 | No fix yet |
| Aug 25 | Red Hat Emacs TRAMP. A local attacker: code execution | High7.8 | No fix yet |
| Aug 25 | Red Hat sos clean: path traversal | High7.8 | No fix yet |