VDB
RHSA-2026%3A2180
RHSA-2026%3A2180
PUBLISHED
CVSS 8.800000190734863 HIGH
A flaw was found in jsonpath. The `value` function is vulnerable to Prototype Pollution, a type of vulnerability that allows an attacker to inject or modify properties of an object's prototype. This can lead to various impacts, including arbitrary code execution, privilege escalation, or denial of service (DoS).
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/ansible-automation-platform/automation-portal@sha256:5ba75c11ba1f6f1b395bc4b6e05c7f543efa16f7d71d75201cabe56a82ff53d8_amd64 as a component of Self-service automation portal 2.0 | *, *, * |
| Red Hat | Self-service automation portal 2.0 |
Timeline
- Feb 5, 2026 CVE Published
- May 1, 2026 Security Advisory
- Jul 27, 2026 CVE Updated
- Jul 27, 2026 Distribution Patch
- Jul 27, 2026 Distribution Patch
- Jul 27, 2026 Security Advisory
References
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform advisory
- https://www.cve.org/CVERecord?id=CVE-2025-61140 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-61140 advisory
- https://access.redhat.com/errata/RHSA-2026:2180 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2180.json advisory
- https://access.redhat.com/security/cve/CVE-2025-61140 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2433946 issue
- https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d advisory
- https://github.com/dchester/jsonpath advisory