Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-90959— Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theft

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 pulpcore 中发现了一个路径遍历漏洞。内容上传 API 接受一个名为 的参数,该参数允许具有文件仓库权限的用户指定一个本地文件 URL,以便 Pulp 下载并存储。URL 方案验证检查使用字符串前缀比较,仅拒绝以 开头的 URL,但 Python 的 URL 解析器可以识别不带双斜杠的 方案,导致验证逻辑与传递给文件下载器的内容之间存在不匹配。具有低权限仓库认证权限的用户可以通过提供精心构造的、包含相对路径遍历序列的 URL,读取 Pulp 服务器进程可访问的任何文件。在包含 Pulp Container

CVSS 8.1 · High EPSS 0.32% · P22
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90959

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theft
Source: CVE Program / CVE List V5
Vulnerability Description
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double slashes, creating a mismatch between what is validated and what is dispatched to the file downloader. An authenticated user with low-privilege repository permissions can supply a specially crafted URL using relative path traversal sequences to read any file accessible to the Pulp server process. In deployments that include Pulp Container, successful exploitation allows an attacker to read the container registry token signing private key and forge bearer tokens, granting unauthorized access to all private container repositories in the affected registry.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6
Red Hat Red Hat Update Infrastructure 4 for Cloud Providers - cpe:/a:redhat:rhui:4::el8
Red Hat Red Hat Update Infrastructure 4 for Cloud Providers - cpe:/a:redhat:rhui:4::el8
Red Hat Red Hat Update Infrastructure 4 for Cloud Providers - cpe:/a:redhat:rhui:4::el8
Red Hat Red Hat Update Infrastructure 5 - cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 - cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 - cpe:/a:redhat:rhui:5::el9

II. Public POCs for CVE-2026-90959

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90959

请登录查看更多情报信息。

Other References for CVE-2026-90959 (2)

Same Patch Batch · Red Hat · 2026-09-24 · 8 CVEs total

CVE-2026-95521 7.8 HIGH Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when i
CVE-2026-95519 7.8 HIGH Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify m
CVE-2026-97185 7.8 HIGH Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file
CVE-2026-94416 6.8 MEDIUM Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery
CVE-2026-97177 6.6 MEDIUM Keycloak-services: keycloak-services: generic user update bypasses denied reset-password p
CVE-2026-97311 4.3 MEDIUM Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups
CVE-2026-97176 4.2 MEDIUM Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cook

IV. Related Vulnerabilities

V. Comments for CVE-2026-90959

No comments yet


Leave a comment