REDHAT-BUG-2544603: Medium severity Pulp Pulp Ansible vulnerability

Published Oct 1, 2026
·
Updated

AUTHTOKEN in pulpansible/app/downloaders.py is a module global. TokenAuthHttpDownloader.getorupdatetoken() returns that global to any downloader in the process. It is not stored per remote or per token URL. The refresh path runs only when the remote has both token and authurl. A worker that has already refreshed one remote's token sends that access token as the bearer for a later remote. The collection remote token field is write-only. Introduced by 57f5775b, first release 0.6.0. It has same root cause as reported pulpcontainer finding (CVE-2026-103868). This is a separate CVE from the pulp-container, as it has different codebase, and independently fixable.

Affected Software

1 affected component
Pulp Pulp Ansible>=0.6.0

Event History

Oct 1, 2026
Data Sourced
via Red Hat·12:19 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are exposed to token crossover?

The issue was introduced in Pulp Ansible 0.6.0. Exposure requires a worker process that handles collection remotes, including at least one remote configured with both a token and an auth_url.

2

What sequence causes a token to be sent to another remote?

A worker first refreshes a token for one remote, then processes a downloader for a later remote in the same process. The later downloader can receive the previously refreshed token because the token is held in a process-wide module global rather than being associated with a specific remote or token URL.

3

Does a remote without both token and auth_url avoid the problem?

Such a remote does not trigger the token refresh path, because refresh runs only when both fields are configured. However, the downloader can still be given a token already cached globally by an earlier remote in the same worker process.

4

How can operators assess whether their environment is at risk?

Identify Pulp Ansible deployments based on code introduced in or after release 0.6.0, then review collection remote configurations for remotes that have both token and auth_url set. Prioritize workers that may process more than one remote in the same process.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203