Server-side Request Forgery Vulnerability in AWX Webhook Mechanism
CVE-2026-71365

7.7HIGH

What is CVE-2026-71365?

A vulnerability in AWX's webhook status callback mechanism allows for server-side request forgery (SSRF). When processing GitHub pull request webhooks, AWX incorrectly extracts the status callback URL from the webhook payload without sufficient validation of the target host. This flaw permits an authenticated user with admin-level access on a webhook-enabled job template to read the webhook signing key and send maliciously crafted GitHub webhook payloads. By providing an arbitrary statuses_url, the attacker can manipulate AWX to post status updates to any endpoint of their choice, potentially exposing sensitive credentials such as the Git Personal Access Token included in the Authorization header.

Affected Version(s)

Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.32-1.el8ap

Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.6.32-1.el9ap

Red Hat Ansible Automation Platform 2.6 1787244009

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.