PT-2026-77190 · Awx · Awx
CVE-2026-71365
·
Published
2026-08-18
·
Updated
2026-08-25
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AWX (affected versions not specified)
Description
A server-side request forgery (SSRF) issue exists in the webhook status callback mechanism. When processing GitHub pull request webhooks, the system extracts the
pull request.statuses url from the payload without validating the target host. An attacker with an admin role on a webhook-enabled job template can use the signing key to forge a signed payload with a malicious pull request.statuses url. This causes the system to send a POST request to an attacker-controlled or internal URL, leaking the configured Git Personal Access Token (PAT) via the Authorization header.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Awx