boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-71365

Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 — Awx: webhook status callback ssrf leaks the git pat
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0049   40.4     —
AFFECTED
  Product                                             Versions     Fixed
  Red Hat Ansible Automation Platform 2.5 for RHEL 8  unspecified  0:4.6.32-1.el8ap
  Red Hat Ansible Automation Platform 2.5 for RHEL 9  unspecified  0:4.6.32-1.el9ap
  Red Hat Ansible Automation Platform 2.6 for RHEL 9  unspecified  0:4.7.16-1.el9ap
  Red Hat Ansible Automation Platform 2.6             unspecified  1787244009
  Red Hat Ansible Automation Platform 2.7             unspecified  1787220257
TIMELINE
  Aug 6   Reserved by redhat
  Aug 18  Published (CNA: redhat)
  Aug 23  PATCH SHIPPED — CVE-2026-71365 (Red Hat Ansible Automation Platform 2.5 for RHEL 8). Fixed in Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.32-1.el8ap.
CWE-918 · CNA: redhat · CVSS v3.1 · 6 references · NVD status: Awaiting Analysis

Description

A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload without validating the target host against the expected Git provider. This URL is persisted in job extra variables and later used to send authenticated status updates. A user with admin role on a webhook-enabled job template can read the template's webhook signing key, forge a signed GitHub webhook payload with an arbitrary statuses_url, and cause AWX to POST status updates to an attacker-controlled or internal URL. The status update request includes the configured Git Personal Access Token (PAT) in the Authorization header, resulting in credential leakage to the attacker-specified endpoint.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 6, 2026ReservedReserved by redhat
August 18, 2026PublishedPublished (CNA: redhat)
August 23, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-71365 (Red Hat Ansible Automation Platform 2.5 for RHEL 8). Fixed in Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.32-1.el8ap.

Affected

Affected products and packages — 5 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8——0:4.6.32-1.el8ap
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9——0:4.6.32-1.el9ap
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9——0:4.7.16-1.el9ap
Red HatRed Hat Ansible Automation Platform 2.6——1787244009
Red HatRed Hat Ansible Automation Platform 2.7——1787220257

Weaknesses

CWE-918

References (6)

Related

Authoritative record: CVE-2026-71365 at cve.org

Vendors: red hat

Weaknesses: CWE-918

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-71365 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.