DEBIAN-CVE-2026-87874

Source
https://security-tracker.debian.org/tracker/CVE-2026-87874
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-87874.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-87874
Upstream
  • CVE-2026-87874
Published
2026-09-09T17:17:53Z
Modified
2026-09-10T05:02:39Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution.

References

Affected packages

Debian:12 / ansible

Package

Name
ansible
Purl
pkg:deb/debian/ansible?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.3.0+dfsg-1
7.7.0+dfsg-1
7.7.0+dfsg-2
7.7.0+dfsg-3
7.7.0+dfsg-3+deb12u1
9.*
9.4.0+dfsg-1
9.5.1+dfsg-1
10.*
10.0.0+dfsg-1
10.0.1+dfsg-1
10.1.0+dfsg-1
10.5.0+dfsg-1
10.5.0+dfsg-2
10.6.0+dfsg-1
11.*
11.1.0+dfsg-1
11.2.0+dfsg-1
12.*
12.0.0~a1+dfsg-1
12.0.0~a2+dfsg-1
12.0.0~a4+dfsg-1
12.0.0~a6+dfsg-1
12.0.0~b1+dfsg-1
12.0.0~b2+dfsg-1
12.0.0~b3+dfsg-1
12.0.0~b5+dfsg-1
12.0.0+dfsg-1
12.2.0+dfsg-1
13.*
13.1.0+dfsg-1
13.4.0+dfsg-1
14.*
14.0.0~a4+dfsg-1
14.0.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-87874.json"

Debian:13 / ansible

Package

Name
ansible
Purl
pkg:deb/debian/ansible?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

12.*
12.0.0~a6+dfsg-1
12.0.0~b1+dfsg-1
12.0.0~b2+dfsg-1
12.0.0~b3+dfsg-1
12.0.0~b5+dfsg-0+deb13u1
12.0.0~b5+dfsg-1
12.0.0+dfsg-0+deb13u1
12.0.0+dfsg-1
12.2.0+dfsg-1
13.*
13.1.0+dfsg-1
13.4.0+dfsg-1
14.*
14.0.0~a4+dfsg-1
14.0.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-87874.json"

Debian:14 / ansible

Package

Name
ansible
Purl
pkg:deb/debian/ansible?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

12.*
12.0.0~a6+dfsg-1
12.0.0~b1+dfsg-1
12.0.0~b2+dfsg-1
12.0.0~b3+dfsg-1
12.0.0~b5+dfsg-1
12.0.0+dfsg-1
12.2.0+dfsg-1
13.*
13.1.0+dfsg-1
13.4.0+dfsg-1
14.*
14.0.0~a4+dfsg-1
14.0.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-87874.json"