Junglewise Threat Intelligence

CVE-2026-79717: Red Hat galaxy_ng server-side request forgery

CVE-2026-79717 · Severity: medium · CVSS 6.4 · Published 2026-08-25

Vendors: Red Hat.

Executive brief

galaxy_ng is the Ansible Galaxy server plugin for Pulp, used to host and manage Ansible content. An authenticated user with namespace management permissions can exploit a server-side request forgery (SSRF) vulnerability to probe internal networks, enumerate reachable IP addresses, and cause denial of service by overloading background workers. This allows an insider threat to map internal infrastructure without direct network access.

Technical details

galaxy_ng contains an SSRF vulnerability (CWE-918) in namespace avatar URL handling. An authenticated user with namespace change permissions can set a namespace avatar URL to an arbitrary internal address (RFC1918 ranges, loopback, cloud metadata endpoints). A background worker fetches this URL without destination validation or timeouts, allowing the attacker to probe reachable internal services and enumerate IPs. The HTTP responses are filtered (only image content is retained) making this a blind SSRF, but the worker can still be pinned with slow/non-responsive targets causing DoS. Patches are available; mitigation involves restricting namespace permissions, implementing egress filtering on workers, and protecting cloud metadata endpoints.

Affected products

  • Red Hat galaxy_ng shipped in Ansible Automation Platform 2.4 through 2.7

Timeline

  • 2026-08-25: disclosed
  • other: Reported by Arpit Jain, independent security researcher

References

Related threats