Ansible automation platform
This hub aggregates every CVE we track for Ansible automation platform, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
56
CVEs tracked
3
Critical
24
High
1
In CISA KEV
Severity distribution
MEDIUM25HIGH24LOW4CRITICAL3
Monthly trend
0
0
1
1
1
1
0
0
0
0
0
1
2
0
0
0
1
2
3
2
7
11
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Ansible automation platform.
- CVE-2026-40192Pillow is vulnerable to a FITS GZIP decompression bomb7.5
- CVE-2025-57847Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions6.4
- CVE-2026-32281Inefficient policy validation in crypto/x5097.5
- CVE-2026-32280Unexpected work during chain building in crypto/x5097.5
- CVE-2026-32283Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls7.5
- CVE-2026-33810Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x5098.2
- CVE-2026-39373JWCrypto: JWE ZIP decompression bomb5.3
- CVE-2026-33033Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload6.5
- CVE-2026-4292Privilege abuse in ModelAdmin.list_editable2.7
- CVE-2026-4277Privilege abuse in GenericInlineModelAdmin9.8
- CVE-2026-3902ASGI header spoofing via underscore/hyphen conflation7.5
- CVE-2026-33748BuildKit Git URL subdir component can cause access to restricted files7.5
- CVE-2026-33699pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream7.5
- CVE-2026-25645Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function4.4
- CVE-2026-33123pypdf has inefficient decoding of array-based streams6.5
Product normalization is registry-driven with AI assist and human review. How it works