Skip to main content
EPSS 0.4%top 71%

CVE-2026-79717: Server-Side Request Forgery (SSRF) in Red Hat Red Hat Ansible Automation Platform 2

0
Medium
VulnerabilityCVE-2026-79717cvecve-2026-79717
Published: 08/25/2026 (08/25/2026, 14:53:45 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Ansible Automation Platform 2

Description

CVE-2026-79717 is a server-side request forgery (SSRF) vulnerability in galaxy_ng, the Ansible Galaxy server plugin for Pulp, part of Red Hat Ansible Automation Platform 2. An authenticated user with namespace management permissions can set a namespace avatar URL to arbitrary addresses, including internal and cloud metadata endpoints. A background worker fetches these URLs without destination checks, enabling internal network probing and IP enumeration. The HTTP client lacks an overall timeout, allowing slow or unresponsive targets to cause denial of service by pinning workers. The vulnerability is rated medium severity with a CVSS score of 6.4. No complete fix is available, but risk can be reduced by restricting permissions and applying network egress filtering.

CVSS v3.1

Score 6.4medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L

Affected software

Red Hat

Red Hat Ansible Automation Platform 2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 18:24:50 UTC

Technical Analysis

The vulnerability exists in galaxy_ng, the Ansible Galaxy server plugin for Pulp, where an authenticated user with namespace management permissions can specify a namespace avatar URL pointing to arbitrary addresses, including internal networks, loopback, or cloud instance metadata endpoints. A background worker fetches the avatar URL without validating the destination, allowing the attacker to probe internal services and enumerate reachable IP addresses. The HTTP client used for fetching does not enforce an overall timeout, which can be exploited to pin workers and cause denial of service. The SSRF is blind, as response bodies are discarded unless they resemble images, so secrets from cloud metadata endpoints are not directly exposed. This vulnerability affects Red Hat Ansible Automation Platform versions 2.4 through 2.7 where galaxy_ng is included as Private Automation Hub. Red Hat rates this vulnerability as moderate (medium) severity with a CVSS 3.1 base score of 6.4, reflecting low confidentiality impact, no integrity impact, and low availability impact due to potential denial of service.

Potential Impact

An authenticated user with namespace-change permissions can cause Pulp workers to send requests to arbitrary internal or cloud metadata addresses, effectively using the server as a proxy to enumerate internal IP addresses and ports. The SSRF is blind, so attackers do not receive response bodies except for image-like responses, limiting direct data exposure. However, the attacker can cause denial of service by exploiting the lack of HTTP client timeouts, pinning background workers with slow or unresponsive targets. This can disrupt normal operation of the affected service. The vulnerability does not allow direct extraction of cloud metadata secrets but enables internal network reconnaissance and potential denial of service.

Mitigation Recommendations

There is no complete mitigation or official patch available for this vulnerability at this time. Red Hat recommends the following risk reduction measures: 1) Restrict the galaxy.change_namespace and galaxy.add_namespace permissions to trusted administrators only to limit who can trigger avatar URL downloads. 2) In cloud deployments, protect instance metadata endpoints using hop-limited controls such as AWS IMDSv2 with HttpPutResponseHopLimit=1 to reduce exposure. 3) Apply egress network filtering on Pulp worker nodes to block access to RFC1918 private IP ranges, loopback, link-local, and cloud metadata addresses that are not required for normal operation. Users should monitor Red Hat advisories for any future updates or fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-08-25T13:39:43.588Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-79717","vendor":"Red Hat"}]

Threat ID: 6a8db470acd9273b495e7a88

Added to database: 08/25/2026, 15:27:44 UTC

Last enriched: 09/10/2026, 18:24:50 UTC

Last updated: 10/07/2026, 18:48:23 UTC

Views: 67

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses