Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93102.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-93102
Upstream
  • CVE-2026-16493
Published
2026-07-21T18:16:57Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-16493 affecting package ansible 2.17.11-1
Details

A flaw was found in ansible-core. The extractcollectionfromgit() function in ansible-core's concreteartifactmanager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection source URI containing git argument injection payloads can achieve arbitrary command execution when a user runs 'ansible-galaxy collection install' with the malicious source. This is an incomplete fix for CVE-2026-11332, which hardened the role install path but missed the equivalent collection install code path.

References

Affected packages

Azure Linux:3 / ansible

Package

Name
ansible
Purl
pkg:rpm/azure-linux/ansible

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.17.11-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93102.json"