CVE-2026-79717: Server-Side Request Forgery (SSRF) in Red Hat Red Hat Ansible Automation Platform 2
Description
CVE-2026-79717 is a server-side request forgery (SSRF) vulnerability in galaxy_ng, the Ansible Galaxy server plugin for Pulp, part of Red Hat Ansible Automation Platform 2. An authenticated user with namespace management permissions can set a namespace avatar URL to arbitrary addresses, including internal and cloud metadata endpoints. A background worker fetches these URLs without destination checks, enabling internal network probing and IP enumeration. The HTTP client lacks an overall timeout, allowing slow or unresponsive targets to cause denial of service by pinning workers. The vulnerability is rated medium severity with a CVSS score of 6.4. No complete fix is available, but risk can be reduced by restricting permissions and applying network egress filtering.
CVSS v3.1
Score 6.4medium
Affected software
Red Hat
Red Hat Ansible Automation Platform 2
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in galaxy_ng, the Ansible Galaxy server plugin for Pulp, where an authenticated user with namespace management permissions can specify a namespace avatar URL pointing to arbitrary addresses, including internal networks, loopback, or cloud instance metadata endpoints. A background worker fetches the avatar URL without validating the destination, allowing the attacker to probe internal services and enumerate reachable IP addresses. The HTTP client used for fetching does not enforce an overall timeout, which can be exploited to pin workers and cause denial of service. The SSRF is blind, as response bodies are discarded unless they resemble images, so secrets from cloud metadata endpoints are not directly exposed. This vulnerability affects Red Hat Ansible Automation Platform versions 2.4 through 2.7 where galaxy_ng is included as Private Automation Hub. Red Hat rates this vulnerability as moderate (medium) severity with a CVSS 3.1 base score of 6.4, reflecting low confidentiality impact, no integrity impact, and low availability impact due to potential denial of service.
Potential Impact
An authenticated user with namespace-change permissions can cause Pulp workers to send requests to arbitrary internal or cloud metadata addresses, effectively using the server as a proxy to enumerate internal IP addresses and ports. The SSRF is blind, so attackers do not receive response bodies except for image-like responses, limiting direct data exposure. However, the attacker can cause denial of service by exploiting the lack of HTTP client timeouts, pinning background workers with slow or unresponsive targets. This can disrupt normal operation of the affected service. The vulnerability does not allow direct extraction of cloud metadata secrets but enables internal network reconnaissance and potential denial of service.
Mitigation Recommendations
There is no complete mitigation or official patch available for this vulnerability at this time. Red Hat recommends the following risk reduction measures: 1) Restrict the galaxy.change_namespace and galaxy.add_namespace permissions to trusted administrators only to limit who can trigger avatar URL downloads. 2) In cloud deployments, protect instance metadata endpoints using hop-limited controls such as AWS IMDSv2 with HttpPutResponseHopLimit=1 to reduce exposure. 3) Apply egress network filtering on Pulp worker nodes to block access to RFC1918 private IP ranges, loopback, link-local, and cloud metadata addresses that are not required for normal operation. Users should monitor Red Hat advisories for any future updates or fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-25T13:39:43.588Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-79717","vendor":"Red Hat"}]
Threat ID: 6a8db470acd9273b495e7a88
Added to database: 08/25/2026, 15:27:44 UTC
Last enriched: 09/10/2026, 18:24:50 UTC
Last updated: 10/07/2026, 18:48:23 UTC
Views: 67
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.