Skip to content
Red HatCVE-2026-84232

Red Hat pulpcore: cross-site scripting

Medium5.4CVE-2026-84232 · Published Sep 1, 2026

A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Ansible Automation Platform 2
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat Satellite 6
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Update Infrastructure 4 for Cloud Providers
Product
all versionsNo fix yet
Red Hat Update Infrastructure 5
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-79

More Red Hat advisories

All Red Hat
Advisory
Red Hat Ansible Automation Platform: missing authorization
Medium6.4Sep 1
Red Hat SFTP backend: uninitialized resource
Medium4.3Sep 1
Red Hat SFTP backend: denial of service
High8.8Sep 1
Red Hat AFP backend: denial of service
Medium6.5Sep 1
Red Hat MTP backend: denial of service
Medium4.3Sep 1
Red Hat OpenShift Container Platform 4: resource exhaustion
High7.5Sep 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.