CVE-2026-106033Medium· 5.4▾ SunlitA DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next q…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser's location.href without verifying its format or scheme. The platform includes built-in URL validation functions designed to block malicious URI schemes (such as javascript: and data:) as well as off-site or protocol-relative redirects, this specific route bypasses those controls. Consequently, an attacker can craft a malicious link that, when accessed by an authenticated user, causes arbitrary JavaScript to execute within the context of the user's session.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102295Medium· 5.4A flaw was found in Quay
CVE-2026-102576Medium· 4.2A flaw was found in Quay
CVE-2026-80048NoneA flaw was found in `sssd-kcm`
CVE-2026-106062High· 7.8A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader
CVE-2026-104046Medium· 6.2A flaw was found in SSSD (System Security Services Daemon)
CVE-2026-104045Medium· 4.7A flaw was found in SSSD