Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-71366— Awx: notification backends allow ssrf and credential leakage

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在多个 AWX 通知后端中发现了服务器端请求伪造(SSRF)漏洞。Webhook、Mattermost、Rocket.Chat 和 Grafana 通知后端将通知模板中配置的 URL 直接用作 HTTP 请求的目标地址,而未对该目标地址是否与私有、回环(loopback)或保留 IP 地址范围相匹配进行验证。组织中的通知管理员可以创建指向内部网络或回环地址的通知模板,从而导致 AWX 控制节点向那些无法从外部访问的服务发起 HTTP 请求。 此外,Webhook 通知后端会跟随 HTTP 重定向,并且在主机发生变更

CVSS 7.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71366

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Awx: notification backends allow ssrf and credential leakage
Source: CVE Program / CVE List V5
Vulnerability Description
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates pointing to internal or loopback addresses, causing the AWX control node to issue HTTP requests to services that are not externally accessible. Additionally, the webhook notification backend follows HTTP redirects and resends configured Basic Authentication credentials to redirect targets regardless of host change, allowing an attacker to exfiltrate notification credentials by redirecting to an attacker-controlled host. The Grafana backend sends its API key in the Authorization header to the configured target URL.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.32-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.6.32-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:4.7.16-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el10
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2

II. Public POCs for CVE-2026-71366

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71366

登录查看更多情报信息。

Other References for CVE-2026-71366 (4)

Same Patch Batch · Red Hat · 2026-08-24 · 9 CVEs total

CVE-2026-78376 8.8 HIGH Webkitgtk: use-after-free of jscvalue function parameters
CVE-2026-71364 7.2 HIGH Awx: project archive extraction allows path traversal file writes
CVE-2026-19685 7.1 HIGH Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user rest
CVE-2026-78465 7.0 HIGH Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
CVE-2026-78367 7.0 HIGH Rpm: rpmbuild gettarspec() crafted tar member name → macro injection
CVE-2026-78323 6.5 MEDIUM Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates
CVE-2026-78475 6.1 MEDIUM Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader
CVE-2026-17113 6.0 MEDIUM Cri-o: cri-o: unvalidated image env var causes daemon crash

IV. Related Vulnerabilities

V. Comments for CVE-2026-71366

No comments yet


Leave a comment