{"schema_version":1,"title":"ansible (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 76 vulnerabilities in ansible (PyPI): 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2023-5115, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/ansible","json_url":"https://junglewise.ai/threats/technologies/ansible.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/ansible","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":76,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":3,"last_365_days":4},"latest":[{"cve":"CVE-2023-5115","cvss":3.1,"epss":0.0101,"slug":"cve-2023-5115-ansible-symlink-attack-vulnerability","title":"PYSEC-2026-1120 - Ansible symlink attack vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:29.360674+00:00","url":"https://junglewise.ai/threats/cve-2023-5115-ansible-symlink-attack-vulnerability"},{"cve":"CVE-2022-3697","cvss":3.1,"epss":0.0077,"slug":"cve-2022-3697-ansible-leaks-password-to-logs","title":"PYSEC-2026-768 - Ansible leaks password to logs","severity":"low","exploited":false,"published_at":"2026-07-07T10:17:22.91268+00:00","url":"https://junglewise.ai/threats/cve-2022-3697-ansible-leaks-password-to-logs"},{"cve":"CVE-2021-20180","cvss":3.1,"epss":0.0031,"slug":"cve-2021-20180-insertion-of-sensitive-information-into-log-file-in-ansible","title":"PYSEC-2026-618 - Insertion of Sensitive Information into Log File in ansible","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:16.795525+00:00","url":"https://junglewise.ai/threats/cve-2021-20180-insertion-of-sensitive-information-into-log-file-in-ansible"},{"cve":"CVE-2025-14010","cvss":5.5,"epss":0.0014,"slug":"cve-2025-14010-ansible-community-general-information-exposure-in-keycloak-user","title":"Ansible community.general information exposure in Keycloak user module","severity":"medium","exploited":false,"published_at":"2025-12-04T10:16:00.81+00:00","url":"https://junglewise.ai/threats/cve-2025-14010-ansible-community-general-information-exposure-in-keycloak-user"},{"cve":"CVE-2021-3620","cvss":3.1,"epss":0.0039,"slug":"cve-2021-3620-ansible-discloses-sensitive-information-in-traceback-error-message","title":"PYSEC-2022-164 - A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclose","severity":"low","exploited":false,"published_at":"2022-03-03T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3620-ansible-discloses-sensitive-information-in-traceback-error-message"},{"cve":"CVE-2021-3583","cvss":3.1,"epss":0.009,"slug":"cve-2021-3583-ansible-template-injection-and-command-injection","title":"PYSEC-2021-358 - A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the t","severity":"low","exploited":false,"published_at":"2021-09-22T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3583-ansible-template-injection-and-command-injection"},{"cve":"CVE-2021-3533","slug":"cve-2021-3533-pysec-2021-126-a-flaw-was-found-in-ansible-if-an-ansible-user-sets","title":"PYSEC-2021-126 - A flaw was found in Ansible if an ansible user sets ANSIBLE_ASYNC_DIR to a subdirectory of a world writable directory. When this occurs, the","severity":"info","exploited":false,"published_at":"2021-06-09T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3533-pysec-2021-126-a-flaw-was-found-in-ansible-if-an-ansible-user-sets"},{"slug":"pysec-2021-125-a-flaw-was-found-in-ansible-where-the-secret-information-419ad58d","title":"PYSEC-2021-125 - A flaw was found in Ansible where the secret information present in async_files are getting disclosed when the user changes the jobdir to a","severity":"info","exploited":false,"published_at":"2021-06-09T12:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2021-125-a-flaw-was-found-in-ansible-where-the-secret-information-419ad58d"},{"cve":"CVE-2020-10729","cvss":3.1,"epss":0.0044,"slug":"cve-2020-10729-insufficiently-random-values-in-ansible","title":"PYSEC-2021-105 - A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal va","severity":"low","exploited":false,"published_at":"2021-05-27T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-10729-insufficiently-random-values-in-ansible"},{"cve":"CVE-2021-20191","cvss":3.1,"epss":0.0035,"slug":"cve-2021-20191-insertion-of-sensitive-information-into-log-file-in-ansible","title":"PYSEC-2021-124 - A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature","severity":"low","exploited":false,"published_at":"2021-05-26T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-20191-insertion-of-sensitive-information-into-log-file-in-ansible"},{"cve":"CVE-2021-20178","cvss":3.1,"epss":0.0034,"slug":"cve-2021-20178-insertion-of-sensitive-information-into-log-file-in-ansible","title":"PYSEC-2021-106 - A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature w","severity":"low","exploited":false,"published_at":"2021-05-26T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-20178-insertion-of-sensitive-information-into-log-file-in-ansible"},{"cve":"CVE-2021-20228","cvss":3.1,"epss":0.0206,"slug":"cve-2021-20228-ansible-exposes-sensitive-information","title":"PYSEC-2021-1 - A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when","severity":"low","exploited":false,"published_at":"2021-04-29T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-20228-ansible-exposes-sensitive-information"},{"cve":"CVE-2021-3447","epss":0.0033,"slug":"cve-2021-3447-pysec-2021-107-a-flaw-was-found-in-several-ansible-modules-where","title":"PYSEC-2021-107 - A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on ma","severity":"info","exploited":false,"published_at":"2021-04-01T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3447-pysec-2021-107-a-flaw-was-found-in-several-ansible-modules-where"},{"cve":"CVE-2020-25635","cvss":3.1,"epss":0.0032,"slug":"cve-2020-25635-ansible-does-not-collect-garbage-after-playbook-run","title":"PYSEC-2020-220 - A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is comple","severity":"low","exploited":false,"published_at":"2020-10-05T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-25635-ansible-does-not-collect-garbage-after-playbook-run"},{"slug":"pysec-2020-221-a-flaw-was-found-in-ansible-base-when-using-the-aws-ssm-576ff457","title":"PYSEC-2020-221 - A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are","severity":"info","exploited":false,"published_at":"2020-10-05T13:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2020-221-a-flaw-was-found-in-ansible-base-when-using-the-aws-ssm-576ff457"},{"cve":"CVE-2020-14365","cvss":3.1,"epss":0.0023,"slug":"cve-2020-14365-improper-verification-of-cryptographic-signature-in-ansible","title":"PYSEC-2020-209 - A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packag","severity":"low","exploited":false,"published_at":"2020-09-23T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-14365-improper-verification-of-cryptographic-signature-in-ansible"},{"cve":"CVE-2020-14330","cvss":3.1,"epss":0.0057,"slug":"cve-2020-14330-improper-output-neutralization-and-improper-encoding-or-escaping","title":"PYSEC-2020-3 - An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content a","severity":"low","exploited":false,"published_at":"2020-09-11T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-14330-improper-output-neutralization-and-improper-encoding-or-escaping"},{"cve":"CVE-2020-14332","cvss":3,"epss":0.0041,"slug":"cve-2020-14332-insertion-of-sensitive-information-into-log-file-and-improper","title":"PYSEC-2020-4 - A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sens","severity":"low","exploited":false,"published_at":"2020-09-11T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-14332-insertion-of-sensitive-information-into-log-file-and-improper"},{"slug":"pysec-2020-180-a-flaw-was-found-in-the-solaris-zone-module-from-the-13cee0ef","title":"PYSEC-2020-180 - A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the","severity":"info","exploited":false,"published_at":"2020-08-26T03:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2020-180-a-flaw-was-found-in-the-solaris-zone-module-from-the-13cee0ef"},{"cve":"CVE-2019-14904","cvss":3.1,"epss":0.0042,"slug":"cve-2019-14904-os-command-injection-and-improper-input-validation-in-ansible","title":"PYSEC-2020-161 - A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the","severity":"low","exploited":false,"published_at":"2020-08-26T03:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-14904-os-command-injection-and-improper-input-validation-in-ansible"},{"cve":"CVE-2020-10744","cvss":3.1,"epss":0.0026,"slug":"cve-2020-10744-exposure-of-resource-to-wrong-sphere-and-insecure-temporary-file","title":"PYSEC-2020-208 - An incomplete fix was found for the fix of the flaw ansible: insecure temporary directory when running become_user from become","severity":"low","exploited":false,"published_at":"2020-05-15T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-10744-exposure-of-resource-to-wrong-sphere-and-insecure-temporary-file"},{"cve":"CVE-2020-1746","cvss":3.1,"epss":0.0041,"slug":"cve-2020-1746-exposure-of-sensitive-information-to-an-unauthorized-actor-in","title":"PYSEC-2020-13 - A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7","severity":"low","exploited":false,"published_at":"2020-05-12T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-1746-exposure-of-sensitive-information-to-an-unauthorized-actor-in"},{"cve":"CVE-2020-10685","cvss":3.1,"epss":0.0038,"slug":"cve-2020-10685-exposure-of-resource-to-wrong-sphere-and-insecure-temporary-file","title":"PYSEC-2020-1 - A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as w","severity":"low","exploited":false,"published_at":"2020-05-11T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-10685-exposure-of-resource-to-wrong-sphere-and-insecure-temporary-file"},{"cve":"CVE-2020-10691","cvss":3.1,"epss":0.0036,"slug":"cve-2020-10691-ansible-path-traversal-in-ansible-galaxy-collection-install","title":"PYSEC-2020-2 - An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. Whe","severity":"low","exploited":false,"published_at":"2020-04-30T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-10691-ansible-path-traversal-in-ansible-galaxy-collection-install"},{"cve":"CVE-2019-14905","cvss":3.1,"epss":0.0074,"slug":"cve-2019-14905-externally-controlled-reference-to-a-resource-in-another-sphere","title":"PYSEC-2020-206 - A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansib","severity":"low","exploited":false,"published_at":"2020-03-31T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-14905-externally-controlled-reference-to-a-resource-in-another-sphere"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"ansible (PyPI)","slug":"ansible","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/ansible"},"most_severe":[{"cve":"CVE-2025-14010","cvss":5.5,"epss":0.0014,"slug":"cve-2025-14010-ansible-community-general-information-exposure-in-keycloak-user","title":"Ansible community.general information exposure in Keycloak user module","severity":"medium","exploited":false,"published_at":"2025-12-04T10:16:00.81+00:00","url":"https://junglewise.ai/threats/cve-2025-14010-ansible-community-general-information-exposure-in-keycloak-user"},{"cve":"CVE-2016-9587","cvss":3.1,"epss":0.1745,"slug":"cve-2016-9587-ansible-is-vulnerable-to-an-improper-input-validation-in-ansible-s","title":"PYSEC-2018-39 - Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. A","severity":"low","exploited":false,"published_at":"2018-04-24T16:29:00+00:00","url":"https://junglewise.ai/threats/cve-2016-9587-ansible-is-vulnerable-to-an-improper-input-validation-in-ansible-s"},{"cve":"CVE-2014-4678","cvss":3.1,"epss":0.0524,"slug":"cve-2014-4678-ansible-code-injection-vulnerability","title":"PYSEC-2020-203 - The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrar","severity":"low","exploited":false,"published_at":"2020-02-20T03:15:00+00:00","url":"https://junglewise.ai/threats/cve-2014-4678-ansible-code-injection-vulnerability"},{"cve":"CVE-2017-7481","cvss":3.1,"epss":0.0478,"slug":"cve-2017-7481-ansible-fails-to-properly-mark-lookup-plugin-results-as-unsafe","title":"PYSEC-2018-41 - Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results","severity":"low","exploited":false,"published_at":"2018-07-19T13:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-7481-ansible-fails-to-properly-mark-lookup-plugin-results-as-unsafe"},{"cve":"CVE-2014-4657","cvss":3.1,"epss":0.0443,"slug":"cve-2014-4657-ansible-remote-code-execution","title":"PYSEC-2020-199 - The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrar","severity":"low","exploited":false,"published_at":"2020-02-20T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2014-4657-ansible-remote-code-execution"},{"cve":"CVE-2017-7550","cvss":3.1,"epss":0.0356,"slug":"cve-2017-7550-ansible-insertion-of-sensitive-information-into-log-file","title":"PYSEC-2017-4 - A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Rem","severity":"low","exploited":false,"published_at":"2017-11-21T17:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-7550-ansible-insertion-of-sensitive-information-into-log-file"},{"cve":"CVE-2014-4967","cvss":3.1,"epss":0.0355,"slug":"cve-2014-4967-ansible-arbitrary-code-execution","title":"PYSEC-2020-205 - Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to","severity":"low","exploited":false,"published_at":"2020-02-18T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2014-4967-ansible-arbitrary-code-execution"},{"cve":"CVE-2014-4966","cvss":3.1,"epss":0.0355,"slug":"cve-2014-4966-ansible-arbitrary-code-execution","title":"PYSEC-2020-204 - Ansible before 1.6.7 does not prevent inventory data with \"{{\" and \"lookup\" substrings, and does not prevent remote data with \"{{\" substring","severity":"low","exploited":false,"published_at":"2020-02-18T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2014-4966-ansible-arbitrary-code-execution"},{"cve":"CVE-2018-10855","cvss":3.1,"epss":0.0311,"slug":"cve-2018-10855-ansible-exposes-sensitive-data-in-log-files-and-on-the-terminal","title":"PYSEC-2018-42 - Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used t","severity":"low","exploited":false,"published_at":"2018-07-03T01:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-10855-ansible-exposes-sensitive-data-in-log-files-and-on-the-terminal"},{"cve":"CVE-2018-16876","cvss":3.1,"epss":0.0248,"slug":"cve-2018-16876-ansible-sensitive-information-disclosure","title":"PYSEC-2019-141 - ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to le","severity":"low","exploited":false,"published_at":"2019-01-03T15:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-16876-ansible-sensitive-information-disclosure"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}