Description
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload without validating the target host against the expected Git provider. This URL is persisted in job extra variables and later used to send authenticated status updates. A user with admin role on a webhook-enabled job template can read the template's webhook signing key, forge a signed GitHub webhook payload with an arbitrary statuses_url, and cause AWX to POST status updates to an attacker-controlled or internal URL. The status update request includes the configured Git Personal Access Token (PAT) in the Authorization header, resulting in credential leakage to the attacker-specified endpoint.
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

AWX’s webhook status callback mechanism permits an attacker with administrative privileges on a webhook‑enabled job template to forge a GitHub webhook payload that specifies an arbitrary statuses_url. The crafted payload causes AWX to POST an authenticated status update to the attacker‑controlled URL, sending the configured Git Personal Access Token in the Authorization header. The result is the exposure of the token and potential unauthorized access to the associated Git repository.

Affected Systems

Red Hat Ansible Automation Platform 2, specifically the AWX component as identified by cpe:/a:redhat:ansible_automation_platform:2. The vulnerability exists in all installed instances of this platform version until a patch is applied; no finer version granularity is specified.

Risk and Exploitability

The CVSS v3 score of 7.7 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV catalog. Exploitation requires the attacker to possess the admin role on a job template that has webhook support, but once that condition is met the attacker can execute the SSRF with a single crafted request. The attack vector is network‑based through forged webhook payloads, with no local privilege escalation required. The impact includes credential theft and potential downstream compromise of code repositories.

Generated by OpenCVE AI on August 18, 2026 at 17:52 UTC.

Remediation

Vendor Workaround

There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Restrict the admin role on webhook-enabled job templates to trusted personnel who already have legitimate access to the associated Git credentials. 2. Use Git credentials with the minimum required scope (e.g., read-only access to the specific repository) to limit the impact of credential leakage. 3. Implement network egress filtering on the Automation Controller nodes to prevent outbound connections to non-allowlisted hosts. Block outbound connections to loopback (127.0.0.0/8), private (RFC1918), and link-local (169.254.0.0/16) address ranges. 4. Monitor for unusual outbound connections from the Controller node to unexpected destinations. 5. Rotate Git PAT credentials periodically and after any suspected compromise.


OpenCVE Recommended Actions

  • Apply the latest update to Red Hat Ansible Automation Platform 2 that fixes the SSRF issue.
  • Restrict the admin role on webhook‑enabled job templates to trusted personnel who already have legitimate access to the associated Git credentials.
  • Use Git credentials with the minimum required scope (e.g., read‑only access to the specific repository) to limit the impact of credential leakage.
  • Implement network egress filtering on the Automation Controller nodes to prevent outbound connections to non‑allowlisted hosts, including loopback, RFC1918, and link‑local address ranges.
  • Monitor for unusual outbound connections from the Controller node to unexpected destinations.
  • Rotate Git PAT credentials periodically and after any suspected compromise.

Generated by OpenCVE AI on August 18, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:ansible_automation_platform:2.7::el9
References

Mon, 24 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ansible Automation Platform Developer
Redhat ansible Automation Platform Inside
CPEs cpe:/a:redhat:ansible_automation_platform:2.5::el8
cpe:/a:redhat:ansible_automation_platform:2.5::el9
cpe:/a:redhat:ansible_automation_platform:2.6::el10
cpe:/a:redhat:ansible_automation_platform:2.6::el9
cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8
cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9
cpe:/a:redhat:ansible_automation_platform_developer:2.6::el10
cpe:/a:redhat:ansible_automation_platform_developer:2.6::el9
cpe:/a:redhat:ansible_automation_platform_inside:2.6::el9
Vendors & Products Redhat ansible Automation Platform Developer
Redhat ansible Automation Platform Inside
References

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload without validating the target host against the expected Git provider. This URL is persisted in job extra variables and later used to send authenticated status updates. A user with admin role on a webhook-enabled job template can read the template's webhook signing key, forge a signed GitHub webhook payload with an arbitrary statuses_url, and cause AWX to POST status updates to an attacker-controlled or internal URL. The status update request includes the configured Git Personal Access Token (PAT) in the Authorization header, resulting in credential leakage to the attacker-specified endpoint.
Title Awx: webhook status callback ssrf leaks the git pat
First Time appeared Redhat
Redhat ansible Automation Platform
Weaknesses CWE-918
CPEs cpe:/a:redhat:ansible_automation_platform:2
Vendors & Products Redhat
Redhat ansible Automation Platform
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Redhat Ansible Automation Platform Ansible Automation Platform Developer Ansible Automation Platform Inside
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-25T08:47:09.117Z

Reserved: 2026-08-06T04:27:34.372Z

Link: CVE-2026-71365

cve-icon Vulnrichment

Updated: 2026-08-19T14:44:14.773Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T16:18:16.157

Modified: 2026-08-25T09:17:32.470

Link: CVE-2026-71365

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-18T15:04:38Z

Links: CVE-2026-71365 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:18:36Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)