High severity7.8NVD Advisory· Published Jun 5, 2026· Updated Aug 20, 2026
CVE-2026-11332
CVE-2026-11332
Description
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ansible-corePyPI | < 2.16.19rc1 | 2.16.19rc1 |
ansible-corePyPI | >= 2.17.0b1, < 2.18.18rc1 | 2.18.18rc1 |
ansible-corePyPI | >= 2.19.0b1, < 2.19.11rc1 | 2.19.11rc1 |
ansible-corePyPI | >= 2.20.0b1, < 2.20.7rc1 | 2.20.7rc1 |
ansible-corePyPI | >= 2.21.0b1, < 2.21.1rc1 | 2.21.1rc1 |
Affected products
14- osv-coords12 versionspkg:rpm/almalinux/ansible-corepkg:rpm/almalinux/ansible-testpkg:rpm/opensuse/ansible-core&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ansible-core&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-core-2.18&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-core-2.19&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-core-2.20&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-lint&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/molecule&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-ansible-compat&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ansible-core&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/ansible-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
< 1:2.16.16-2.el10_2.1+ 11 more
- (no CPE)range: < 1:2.16.16-2.el10_2.1
- (no CPE)range: < 1:2.16.16-2.el10_2.1
- (no CPE)range: < 2.18.3-160000.3.1
- (no CPE)range: < 2.21.0-3.1
- (no CPE)range: < 2.18.18-1.1
- (no CPE)range: < 2.19.11-1.1
- (no CPE)range: < 2.20.7-1.1
- (no CPE)range: < 26.8.0-1.1
- (no CPE)range: < 26.8.0-1.1
- (no CPE)range: < 26.8.0-1.1
- (no CPE)range: < 2.18.3-160000.3.1
- (no CPE)range: < 2.18.3-160000.3.1
Patches
Vulnerability mechanics
References
17- github.com/advisories/GHSA-w8p5-mx5w-cpqjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-11332ghsaADVISORY
- access.redhat.com/security/cve/CVE-2026-11332nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/ansible/ansible/commit/edee59aa15abcc74d920bb3e9c3835ab8db05a2fghsaWEB
- github.com/ansible/ansible/pull/87070ghsaWEB
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11332.jsonnvdWEB
- access.redhat.com/errata/RHSA-2026:42078nvd
- access.redhat.com/errata/RHSA-2026:42079nvd
- access.redhat.com/errata/RHSA-2026:42080nvd
- access.redhat.com/errata/RHSA-2026:46836nvd
- access.redhat.com/errata/RHSA-2026:50340nvd
- access.redhat.com/errata/RHSA-2026:50344nvd
- access.redhat.com/errata/RHSA-2026:50357nvd
- access.redhat.com/errata/RHSA-2026:50479nvd
- access.redhat.com/errata/RHSA-2026:57148nvd
- access.redhat.com/errata/RHSA-2026:57149nvd
News mentions
0No linked articles in our index yet.