<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:40:13.127382+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-00285</id>
    <title>bdu:2023-00285</title>
    <updated>2026-10-04T03:40:13.155930+00:00</updated>
    <content>bdu:2023-00285</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-00285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2021-3583</id>
    <title>BREW-ansible-CVE-2021-3583</title>
    <updated>2026-10-04T03:40:13.155989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2021-3583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-20924</id>
    <title>EUVD-2026-20924</title>
    <updated>2026-10-04T03:40:13.156032+00:00</updated>
    <content>EUVD-2026-20924</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-20924"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3583</id>
    <title>fkie_cve-2021-3583</title>
    <updated>2026-10-04T03:40:13.156046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2pfh-q76x-gwvm</id>
    <title>GHSA-2pfh-q76x-gwvm — Improper Input Validation and Command Injection in Ansible</title>
    <updated>2026-10-04T03:40:13.156070+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2pfh-q76x-gwvm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3583</id>
    <title>gsd-2021-3583</title>
    <updated>2026-10-04T03:40:13.156095+00:00</updated>
    <content>gsd-2021-3583</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3583</id>
    <title>msrc_CVE-2021-3583 — A flaw was found in Ansible where a user's controller is vulnerable to template injection. This issue can occur through…</title>
    <updated>2026-10-04T03:40:13.156107+00:00</updated>
    <content>msrc_CVE-2021-3583</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-3583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1647</id>
    <title>OESA-2025-1647 — ansible security update</title>
    <updated>2026-10-04T03:40:13.156125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: ansible</p>
<p>\

Security Fix(es):</p>
<p>A flaw was found in Ansible, where a user&amp;apos;s controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.(CVE-2021-3583)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10615-1</id>
    <title>openSUSE-SU-2024:10615-1 — ansible-2.9.24-1.2 on GA media</title>
    <updated>2026-10-04T03:40:13.156149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ansible-2.9.24-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10615-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2021-358</id>
    <title>PYSEC-2021-358</title>
    <updated>2026-10-04T03:40:13.156188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2021-358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2021:2703</id>
    <title>RHBA-2021:2703 — Red Hat Bug Fix Advisory: Red Hat Ansible Automation Platform Product Release</title>
    <updated>2026-10-04T03:40:13.156208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ansible: Template Injection through yaml multi-line strings with ansible facts used in template.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2021:2703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:4152-1</id>
    <title>SUSE-SU-2021:4152-1 — Security update for ansible</title>
    <updated>2026-10-04T03:40:13.156225+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ansible</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:4152-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3583</id>
    <title>UBUNTU-CVE-2021-3583</title>
    <updated>2026-10-04T03:40:13.156259+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible, Ubuntu:Pro:22.04:LTS: ansible, Ubuntu:24.04:LTS: ansible, Ubuntu:25.10: ansible, Ubuntu:26.04:LTS: ansible</p>
<p>A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The highest threat from this vulnerability is to confidentiality and integrity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1355</id>
    <title>WID-SEC-W-2022-1355 — Ansible: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode und Offenlegung von Daten</title>
    <updated>2026-10-04T03:40:13.156315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Ansible ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen und Daten offenzulegen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1355"/>
  </entry>
</feed>
