Technology · PyPI
ansible (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 76 vulnerabilities in ansible (PyPI): 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2023-5115, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest ansible (PyPI) vulnerabilities
- CVE-2023-5115: PYSEC-2026-1120 - Ansible symlink attack vulnerabilitylowCVSS 3.1EPSS 1.0%
- CVE-2022-3697: PYSEC-2026-768 - Ansible leaks password to logslowCVSS 3.1EPSS 0.8%
- CVE-2021-20180: PYSEC-2026-618 - Insertion of Sensitive Information into Log File in ansiblelowCVSS 3.1EPSS 0.3%
- CVE-2025-14010: Ansible community.general information exposure in Keycloak user modulemediumCVSS 5.5EPSS 0.1%
- CVE-2021-3620: PYSEC-2022-164 - A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the…lowCVSS 3.1EPSS 0.4%
- CVE-2021-3583: PYSEC-2021-358 - A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can…lowCVSS 3.1EPSS 0.9%
- CVE-2021-3533: PYSEC-2021-126 - A flaw was found in Ansible if an ansible user sets ANSIBLE_ASYNC_DIR to a subdirectory of a world…info
- PYSEC-2021-125 - A flaw was found in Ansible where the secret information present in async_files are getting disclosed when the user…info
- CVE-2020-10729: PYSEC-2021-105 - A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of…lowCVSS 3.1EPSS 0.4%
- CVE-2021-20191: PYSEC-2021-124 - A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default…lowCVSS 3.1EPSS 0.4%
- CVE-2021-20178: PYSEC-2021-106 - A flaw was found in ansible module where credentials are disclosed in the console log by default and not…lowCVSS 3.1EPSS 0.3%
- CVE-2021-20228: PYSEC-2021-1 - A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not…lowCVSS 3.1EPSS 2.1%
- CVE-2021-3447: PYSEC-2021-107 - A flaw was found in several ansible modules, where parameters containing credentials, such as secrets…infoEPSS 0.3%
- CVE-2020-25635: PYSEC-2020-220 - A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not…lowCVSS 3.1EPSS 0.3%
- PYSEC-2020-221 - A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file…info
- CVE-2020-14365: PYSEC-2020-209 - A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x…lowCVSS 3.1EPSS 0.2%
- CVE-2020-14330: PYSEC-2020-3 - An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where…lowCVSS 3.1EPSS 0.6%
- CVE-2020-14332: PYSEC-2020-4 - A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode…lowCVSS 3EPSS 0.4%
- PYSEC-2020-180 - A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the…info
- CVE-2019-14904: PYSEC-2020-161 - A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for…lowCVSS 3.1EPSS 0.4%
- CVE-2020-10744: PYSEC-2020-208 - An incomplete fix was found for the fix of the flaw ansible: insecure temporary directory when running…lowCVSS 3.1EPSS 0.3%
- CVE-2020-1746: PYSEC-2020-13 - A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x…lowCVSS 3.1EPSS 0.4%
- CVE-2020-10685: PYSEC-2020-1 - A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before…lowCVSS 3.1EPSS 0.4%
- CVE-2020-10691: PYSEC-2020-2 - An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running…lowCVSS 3.1EPSS 0.4%
- CVE-2019-14905: PYSEC-2020-206 - A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before…lowCVSS 3.1EPSS 0.7%
Most severe ansible (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-14010: Ansible community.general information exposure in Keycloak user modulemediumCVSS 5.5EPSS 0.1%
- CVE-2016-9587: PYSEC-2018-39 - Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of…lowCVSS 3.1EPSS 17.4%
- CVE-2014-4678: PYSEC-2020-203 - The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows…lowCVSS 3.1EPSS 5.2%
- CVE-2017-7481: PYSEC-2018-41 - Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an…lowCVSS 3.1EPSS 4.8%
- CVE-2014-4657: PYSEC-2020-199 - The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows…lowCVSS 3.1EPSS 4.4%
- CVE-2017-7550: PYSEC-2017-4 - A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters…lowCVSS 3.1EPSS 3.6%
- CVE-2014-4967: PYSEC-2020-205 - Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute…lowCVSS 3.1EPSS 3.5%
- CVE-2014-4966: PYSEC-2020-204 - Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not…lowCVSS 3.1EPSS 3.5%
- CVE-2018-10855: PYSEC-2018-42 - Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks…lowCVSS 3.1EPSS 3.1%
- CVE-2018-16876: PYSEC-2019-141 - ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode…lowCVSS 3.1EPSS 2.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/ansible.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "ansible (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/ansible, 26 September 2026.