Skip to content
Red HatCVE-2026-79717

Red Hat Ansible Automation Platform 2: server-side request forgery

Medium6.4CVE-2026-79717 · Published Aug 25, 2026 · updated Aug 28, 2026

A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or cloud instance metadata endpoints. A background worker fetches that URL without checking the destination, which lets the attacker probe internal services and enumerate reachable IP addresses. The HTTP client is also configured without an overall timeout, so a slow or non-responsive target can pin workers and cause a denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Ansible Automation Platform 2
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: type confusion
Medium5.7Aug 25
Red Hat Enterprise Linux: stack buffer overflow
High7.6Aug 25
Red Hat file-xwd plugin: out-of-bounds read
Medium4.4Aug 25
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing
Medium5.3Aug 25
Red Hat Emacs TRAMP. A local attacker: code execution
High7.8Aug 25
Red Hat sos clean: path traversal
High7.8Aug 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.