VYPR

AWX

by Awx

CVEs (3)

  • CVE-2026-71365HigAug 18, 2026
    risk 0.50cvss 7.7epss

    A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload without validating the target…

  • CVE-2026-16544MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_update_events,…

  • CVE-2026-12726MedJun 19, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is…