Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106033— Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ansible 平台 UI 中存在一个基于 DOM 的跨站脚本(XSS)漏洞,该漏洞源于应用程序在重定向路由中对输入缺乏有效验证。具体而言,应用程序从 查询参数中提取目标地址,并直接将其赋值给浏览器的 ,而未验证其格式或协议方案(scheme)。尽管该平台上集成了内置的 URL 验证功能,旨在阻止恶意 URI 方案(如 和 )以及指向外部站点或协议相关的重定向,但此特定重定向路由绕过了这些安全控制措施。因此,攻击者可构造恶意链接,当认证用户访问该链接时,将在该用户会话上下文中执行任意 JavaScript 代码。

CVSS 5.4 · Medium

Affected Version Matrix 9

VendorProduct Version RangeStatus
Red Hat Red Hat Ansible Automation Platform 2 any affected
any affected
any affected
any affected
any affected
any affected
any affected
any affected
Red Hat Red Hat Hardened Images any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106033

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter
Source: CVE Program / CVE List V5
Vulnerability Description
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser's location.href without verifying its format or scheme. The platform includes built-in URL validation functions designed to block malicious URI schemes (such as javascript: and data:) as well as off-site or protocol-relative redirects, this specific route bypasses those controls. Consequently, an attacker can craft a malicious link that, when accessed by an authenticated user, causes arbitrary JavaScript to execute within the context of the user's session.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1

II. Public POCs for CVE-2026-106033

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106033

请登录查看更多情报信息。

Other References for CVE-2026-106033 (2)

Same Patch Batch · Red Hat · 2026-10-06 · 26 CVEs total

CVE-2026-106062 7.8 HIGH Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface file
CVE-2026-101258 7.8 HIGH Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write and procedur
CVE-2026-83550 7.1 HIGH Postgres-exporter: net/http/pprof exposed on metrics listener
CVE-2026-104048 6.8 MEDIUM Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation
CVE-2026-92821 6.8 MEDIUM Sssd: sssd: access control bypass via premature ldap access rule evaluation
CVE-2026-106063 6.3 MEDIUM Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions
CVE-2026-104046 6.2 MEDIUM Sssd: sssd: denial of service via incomplete identity provider authentication requests
CVE-2026-104044 6.2 MEDIUM Sssd: sssd: denial of service via crafted passkey kerberos authentication request
CVE-2026-104038 5.9 MEDIUM Sssd: sssd: denial of service via missing sid extension in certificate mapping
CVE-2026-104036 5.8 MEDIUM Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin
CVE-2026-104031 5.5 MEDIUM Sssd: sssd: denial of service via memory exhaustion in autofs responder
CVE-2026-104032 5.5 MEDIUM Sssd: sssd: denial of service via unprivileged autofs cache invalidation
CVE-2026-104035 5.5 MEDIUM Sssd: sssd: denial of service via memory exhaustion in kcm responder
CVE-2026-104037 5.5 MEDIUM Sssd: sssd: denial of service via packet length underflow in autofs responder
CVE-2026-104041 5.5 MEDIUM Sssd: sssd: denial of service via unbounded negative cache growth
CVE-2026-104042 5.5 MEDIUM Sssd: sssd: denial of service via out-of-bounds read in pam responder
CVE-2026-104043 5.5 MEDIUM Sssd: sssd: denial of service via undersized packet parsing in nss responder
CVE-2026-105305 5.4 MEDIUM Keycloak-services: keycloak-services: device authorization grant bypasses per-client minim
CVE-2026-104033 5.4 MEDIUM Sssd: sssd: access control bypass via improper ldap shadow expiration check
CVE-2026-104047 5.3 MEDIUM Sssd: sssd: information disclosure via query injection in entra id lookups

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-106033

No comments yet


Leave a comment