Ansible automation platform
This hub aggregates every CVE we track for Ansible automation platform, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
59
CVEs tracked
3
Critical
26
High
2
In CISA KEV
Severity distribution
HIGH26MEDIUM26LOW4CRITICAL3
Monthly trend
1
1
1
0
0
0
0
0
1
2
0
0
0
1
2
3
2
7
11
1
2
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Ansible automation platform.
- CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge7.0
- CVE-2026-46625JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection7.5
- CVE-2026-48710Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checksKEV6.5
- CVE-2026-40192Pillow is vulnerable to a FITS GZIP decompression bomb7.5
- CVE-2025-57847Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions6.4
- CVE-2026-32281Inefficient policy validation in crypto/x5097.5
- CVE-2026-32280Unexpected work during chain building in crypto/x5097.5
- CVE-2026-32283Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls7.5
- CVE-2026-33810Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x5098.2
- CVE-2026-39373JWCrypto: JWE ZIP decompression bomb5.3
- CVE-2026-33033Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload6.5
- CVE-2026-4292Privilege abuse in ModelAdmin.list_editable2.7
- CVE-2026-4277Privilege abuse in GenericInlineModelAdmin9.8
- CVE-2026-3902ASGI header spoofing via underscore/hyphen conflation7.5
- CVE-2026-33748BuildKit Git URL subdir component can cause access to restricted files7.5
Product normalization is registry-driven with AI assist and human review. How it works