PT-2026-97497 · Jinja · Jinja

·

CVE-2026-71463

·

Published

2026-09-23

·

Updated

2026-09-25

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The notification template Jinja AST whitelist only inspects static Getattr nodes. This allows dynamic subscripts, such as job['job'+' env'], and conditional gating, such as {% if job.id > 100 %}, to bypass both the AST check and the test-render process. At runtime, the gated branch executes and exceptions write full tracebacks into the notification body, which is then POSTed to an attacker-controlled webhook URL. This process leaks sensitive information, including install paths, Python version, and source line numbers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71463
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Jinja