VDB
RHSA-2026%3A2181
RHSA-2026%3A2181
PUBLISHED
CVSS 8.800000190734863 HIGH
A flaw was found in jsonpath. The `value` function is vulnerable to Prototype Pollution, a type of vulnerability that allows an attacker to inject or modify properties of an object's prototype. This can lead to various impacts, including arbitrary code execution, privilege escalation, or denial of service (DoS).
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/ansible-automation-platform/automation-portal@sha256:140ed733a2820c7087000878f99ca3010613743ccc43c667956dc1d74302fd76_amd64 as a component of Red Hat Ansible Automation Platform 2.1 | * |
Timeline
- Feb 5, 2026 CVE Published
- Apr 30, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2026:2181 advisory
- https://access.redhat.com/security/cve/CVE-2025-61140 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2181.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2433946 issue
- https://www.cve.org/CVERecord?id=CVE-2025-61140 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-61140 advisory
- https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d advisory
- https://github.com/dchester/jsonpath advisory