{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-84232","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2026-09-01T12:16:44.850Z","datePublished":"2026-09-01T15:18:59.649Z","dateUpdated":"2026-09-17T07:22:08.585Z"},"containers":{"cna":{"title":"Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content","metrics":[{"other":{"content":{"value":"Moderate","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application."}],"affected":[{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-24/hub-rhel8","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-25/hub-rhel8","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-26/hub-rhel9","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-27/hub-rhel9","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.11-pulpcore","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.12-pulpcore","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3x-pulpcore","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-pulpcore","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.12-pulpcore","defaultStatus":"affected","cpes":["cpe:/a:redhat:satellite:6"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-pulpcore","defaultStatus":"affected","cpes":["cpe:/a:redhat:satellite:6"]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 4 for Cloud Providers","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-pulpcore","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:rhui:4::el8"]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhui5/rhua-rhel9","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:rhui:5::el9"]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhui5/rhua-tp-rhel9","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:rhui:5::el9"]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-84232","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526807","name":"RHBZ#2526807","tags":["issue-tracking","x_refsource_REDHAT"]}],"datePublic":"2026-09-01T00:00:00.000Z","problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","workarounds":[{"lang":"en","value":"If immediate update is not possible, administrators can add security headers to the Apache reverse proxy configuration for the /pulp/content/ path. On Satellite, add the following to the Apache configuration (e.g., via a custom .conf file in /etc/httpd/conf.d/ or via a Puppet override):\n\n```\n  <Location /pulp/content>\n    Header set Content-Disposition \"attachment\"\n    Header set X-Content-Type-Options \"nosniff\"\n    Header set Content-Security-Policy \"default-src 'none'; sandbox\"\n  </Location>\n```\nThis forces all content downloads rather than inline rendering, and blocks script execution even if Content-Disposition is somehow bypassed.\n\nAfter applying, restart Apache: ```systemctl restart httpd```\nAlternatively, restrict file upload permissions in Satellite to only trusted users who require content management capabilities."}],"timeline":[{"lang":"en","time":"2026-09-01T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-01T00:00:00.000Z","value":"Made public."}],"credits":[{"lang":"en","value":"Red Hat would like to thank Nathan Hardy for reporting this issue."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-09-17T07:22:08.585Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-01T17:43:35.765110Z","id":"CVE-2026-84232","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-01T17:43:42.487Z"}}]}}