Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content
Published Sep 1, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.24%
Description
A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | affected |
|
No data.
No data.
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/hub-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/hub-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/hub-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/hub-rhel9
Not affected
Red Hat Ansible Automation Platform 2
python-pulpcore
Not affected
Red Hat Ansible Automation Platform 2
python3.11-pulpcore
Not affected
Red Hat Ansible Automation Platform 2
python3.12-pulpcore
Not affected
Red Hat Ansible Automation Platform 2
python3x-pulpcore
Not affected
Red Hat Satellite 6
python-pulpcore
Affected
Red Hat Satellite 6
python3.12-pulpcore
Affected
Red Hat Update Infrastructure 4 for Cloud Providers
python-pulpcore
Not affected
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9
Not affected
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/hub-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/hub-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/hub-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/hub-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | python-pulpcore | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | python3.11-pulpcore | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | python3.12-pulpcore | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | python3x-pulpcore | Not affected | n/a |
| Red Hat Satellite 6 | python-pulpcore | Affected | n/a |
| Red Hat Satellite 6 | python3.12-pulpcore | Affected | n/a |
| Red Hat Update Infrastructure 4 for Cloud Providers | python-pulpcore | Not affected | n/a |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9 | Not affected | n/a |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
If immediate update is not possible, administrators can add security headers to the Apache reverse proxy configuration for the /pulp/content/ path. On Satellite, add the following to the Apache configuration (e.g., via a custom .conf file in /etc/httpd/conf.d/ or via a Puppet override):
``` <Location /pulp/content> Header set Content-Disposition "attachment" Header set X-Content-Type-Options "nosniff" Header set Content-Security-Policy "default-src 'none'; sandbox" </Location> ``` This forces all content downloads rather than inline rendering, and blocks script execution even if Content-Disposition is somehow bypassed.
After applying, restart Apache: ```systemctl restart httpd``` Alternatively, restrict file upload permissions in Satellite to only trusted users who require content management capabilities.
Red Hat statement
Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. This vulnerability affects pulpcore's content serving application, which is an aiohttp process separate from the Django REST API. The confidentiality and integrity impact is limited because the session cookie in the host application (Foreman/Satellite) is set with the HttpOnly attribute, which prevents direct session token theft via JavaScript. The attacker's script can read visible page content and make authenticated API requests on behalf of the victim through the browser, but cannot exfiltrate the session itself or gain persistent access beyond the victim's active browser session. There is no availability impact. ``` In Red Hat Satellite, the /pulp/content/ path shares the same origin (protocol, hostname, and port) as the Satellite web UI, making the XSS effective against Satellite sessions. ``` ``` Ansible Automation Platform and RHUI also ship pulpcore, but they do not use pulp_file repositories and therefore are not affected by this vulnerability. ```
Red Hat mitigation
If immediate update is not possible, administrators can add security headers to the Apache reverse proxy configuration for the /pulp/content/ path. On Satellite, add the following to the Apache configuration (e.g., via a custom .conf file in /etc/httpd/conf.d/ or via a Puppet override): ``` <Location /pulp/content> Header set Content-Disposition "attachment" Header set X-Content-Type-Options "nosniff" Header set Content-Security-Policy "default-src 'none'; sandbox" </Location> ``` This forces all content downloads rather than inline rendering, and blocks script execution even if Content-Disposition is somehow bypassed. After applying, restart Apache: ```systemctl restart httpd``` Alternatively, restrict file upload permissions in Satellite to only trusted users who require content management capabilities.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Sep-Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.24% (0.00235) | 13.07th | v5 (v2026.06.15) |
| Sep 2, 2026 | 0.18% (0.00176) | 7.26th | v5 (v2026.06.15) |
References (4)
- https://access.redhat.com/security/cve/CVE-2026-84232 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2526807 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-84232
- https://www.cve.org/CVERecord?id=CVE-2026-84232
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-84232 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2526807 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-84232 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-84232 |
Change history (0)
No recorded changes yet.