Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-71365
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 — Awx: webhook status callback ssrf leaks the git pat
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C H N N 7.7 .0049 40.4 —
AFFECTED
Product Versions Fixed
Red Hat Ansible Automation Platform 2.5 for RHEL 8 unspecified 0:4.6.32-1.el8ap
Red Hat Ansible Automation Platform 2.5 for RHEL 9 unspecified 0:4.6.32-1.el9ap
Red Hat Ansible Automation Platform 2.6 for RHEL 9 unspecified 0:4.7.16-1.el9ap
Red Hat Ansible Automation Platform 2.6 unspecified 1787244009
Red Hat Ansible Automation Platform 2.7 unspecified 1787220257
TIMELINE
Aug 6 Reserved by redhat
Aug 18 Published (CNA: redhat)
Aug 23 PATCH SHIPPED — CVE-2026-71365 (Red Hat Ansible Automation Platform 2.5 for RHEL 8). Fixed in Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.32-1.el8ap.
Description
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload without validating the target host against the expected Git provider. This URL is persisted in job extra variables and later used to send authenticated status updates. A user with admin role on a webhook-enabled job template can read the template's webhook signing key, forge a signed GitHub webhook payload with an arbitrary statuses_url, and cause AWX to POST status updates to an attacker-controlled or internal URL. The status update request includes the configured Git Personal Access Token (PAT) in the Authorization header, resulting in credential leakage to the attacker-specified endpoint.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 6, 2026 | Reserved | Reserved by redhat |
| August 18, 2026 | Published | Published (CNA: redhat) |
| August 23, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-71365 (Red Hat Ansible Automation Platform 2.5 for RHEL 8). Fixed in Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.32-1.el8ap. |
Affected
Affected products and packages — 5 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | — | — | 0:4.6.32-1.el8ap |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | — | — | 0:4.6.32-1.el9ap |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | — | — | 0:4.7.16-1.el9ap |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | — | — | 1787244009 |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | — | — | 1787220257 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-71365 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.