{"id":"CVE-2026-71463","title":"Notification template Jinja AST whitelist only inspects\n              static Getattr nodes","summary":"Notification template Jinja AST whitelist only inspects\n              static Getattr nodes. Dynamic subscripts (job['job'+'_env'])\n              and {% if job.id > 100 %} conditional gating bypass both\n              the AST check and the…","severity":"low","cvss":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-209"],"vendor":"Red Hat","product":"automation-controller","affected":["automation-controller (all versions)","automation-controller (all versions)","automation-controller (all versions)","ansible-automation-platform-26/controller-rhel9 (all versions)","ansible-automation-platform-27/controller-rhel9 (all versions)"],"published":"2026-09-23","updated":"2026-09-24","sourceUpdated":"2026-09-24T04:17:51.390","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71463","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:71113","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:71114","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-71463","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2512372","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T19:31:04.464Z","slug":"CVE-2026-71463","body":"## Overview\n\nNotification template Jinja AST whitelist only inspects\n              static Getattr nodes. Dynamic subscripts (job['job'+'_env'])\n              and {% if job.id > 100 %} conditional gating bypass both\n              the AST check and the test-render (stub has small job.id).\n              At runtime, the gated branch executes and exceptions write\n              full tracebacks into notification body, which is POSTed\n              to attacker-controlled webhook URL. Leaks install paths,\n              Python version, source line numbers.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":15,"depthScoreParts":{"impact":14.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}