pulpcore-obsolete-packages vulnerabilities
CVEs whose affected-version data names the pulpcore-obsolete-packages package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-90959High· 8.1A path traversal vulnerability was found in pulpcore
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme valida…
▾ TwilightRed Hat · ansible-automation-platform-24/hub-rhel8via NVD
CVE-2026-11332High· 7.8A flaw was found in ansible-core
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can in…
▾ TwilightRed Hat · ansible-coreEPSS 0.22%via NVD