CVE Tools

Ansible Automation Platform

59 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Ansible Automation Platform, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Ansible Automation Platform CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Ansible Automation Platform CVEs per month
MonthCVEs
2024-101
2024-111
2024-121
2025-010
2025-020
2025-030
2025-040
2025-050
2025-061
2025-072
2025-080
2025-090
2025-100
2025-111
2025-122
2026-013
2026-022
2026-037
2026-0411
2026-051
2026-062
2026-070
2026-080
2026-090

Severity

How the 59 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical35%
  • High2644%
  • Medium2644%
  • Low47%

Latest CVEs

The 15 most recently published vulnerabilities affecting Ansible Automation Platform.

  1. CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge7.0
  2. CVE-2026-46625JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection7.5
  3. CVE-2026-48710Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks6.5
  4. CVE-2026-40192Pillow is vulnerable to a FITS GZIP decompression bomb7.5
  5. CVE-2025-57847Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions6.4
  6. CVE-2026-32281Inefficient policy validation in crypto/x5097.5
  7. CVE-2026-32280Unexpected work during chain building in crypto/x5097.5
  8. CVE-2026-32283Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls7.5
  9. CVE-2026-33810Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x5098.2
  10. CVE-2026-39373JWCrypto: JWE ZIP decompression bomb5.3
  11. CVE-2026-33033Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload6.5
  12. CVE-2026-4292Privilege abuse in ModelAdmin.list_editable2.7
  13. CVE-2026-4277Privilege abuse in GenericInlineModelAdmin9.8
  14. CVE-2026-3902ASGI header spoofing via underscore/hyphen conflation7.5
  15. CVE-2026-33748BuildKit Git URL subdir component can cause access to restricted files7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store