VDB

RHSA-2026%3A2181

RHSA-2026%3A2181 PUBLISHED CVSS 8.800000190734863 HIGH

A flaw was found in jsonpath. The `value` function is vulnerable to Prototype Pollution, a type of vulnerability that allows an attacker to inject or modify properties of an object's prototype. This can lead to various impacts, including arbitrary code execution, privilege escalation, or denial of service (DoS).

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
dchesterjsonpath
Red Hatregistry.redhat.io/ansible-automation-platform/automation-portal@sha256:140ed733a2820c7087000878f99ca3010613743ccc43c667956dc1d74302fd76_amd64 as a component of Red Hat Ansible Automation Platform 2.1*, *
Red Hatregistry.redhat.io/ansible-automation-platform/automation-portal@sha256:140ed733a2820c7087000878f99ca3010613743ccc43c667956dc1d74302fd76_amd64
Red Hatregistry.redhat.io/ansible-automation-platform/automation-portal@sha256:140ed733a2820c7087000878f99ca3010613743ccc43c667956dc1d74302fd76_amd64 as a component of Self-service automation portal 2.1*

Timeline

  • Feb 5, 2026 CVE Published
  • Jul 21, 2026 Distribution Patch
  • Jul 27, 2026 CVE Updated
  • Jul 27, 2026 Distribution Patch
  • Jul 27, 2026 Security Advisory
  • Jul 27, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›