StackRadar

CVE-2026-11332

High

Advisory

Published 5 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 2
affected packages

ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
ansible-corepypi2.14.5, 2.14.18, 2.15.3, 2.15.6+5 more2.16.19rc1, 2.18.18rc1, 2.20.7rc19
ansibledeb2.5.3-1ppa~trustyno fix listed2
OSV records
GHSA-w8p5-mx5w-cpqjUBUNTU-CVE-2026-11332
Also known as
PYSEC-2026-3458

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
semaphoresemaphoreuiOfficialVerified publisher16.2.21 of 1See more

semaphore semaphoreui 16.2.2

1 of the 1 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.18.3e9260bfa8255
ansible-core@2.20.5
2.20.7rc1

Open the chart page →

2,221
awx-operatorawx-operator-helm3.2.11 of 2See more

awx-operator awx-operator-helm 3.2.1

1 of the 2 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
ansible-core@2.15.8
2.16.19rc1

Open the chart page →

9,868
pmmpercona1.9.11 of 1See more

pmm percona 1.9.1

1 of the 1 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
percona/pmm-server:3.9.1003f9c25f842
ansible-core@2.14.18
2.16.19rc1

Open the chart page →

790
kiali-operatorkiali2.31.01 of 1See more

kiali-operator kiali 2.31.0

1 of the 1 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
quay.io/kiali/kiali-operator:v2.31.0f837d8f25545
ansible-core@2.18.3
2.18.18rc1

Open the chart page →

1,157
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
ghcr.io/grycap/im:latest06a16d4f279f
ansible-core@2.15.13
2.16.19rc1

Open the chart page →

4,132
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
ansible-core@2.20.2
2.20.7rc1

Open the chart page →

5,558
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
ansible@2.5.3-1ppa~trusty
no fix listed
galaxy/galaxy-stable:v18.018e577a626dfd
ansible@2.5.3-1ppa~trusty
no fix listed

Open the chart page →

70,895
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
ansible-core@2.15.3
2.16.19rc1

Open the chart page →

12,754
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
ansible-core@2.14.5
2.16.19rc1

Open the chart page →

3,337
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-11332.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
ansible-core@2.15.6
2.16.19rc1

Open the chart page →

18,756

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
galaxy/galaxy-init:v18.010267bad550e6
ansible@2.5.3-1ppa~trusty
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
ansible@2.5.3-1ppa~trusty
no fix listed
1
percona/pmm-server:3.9.1003f9c25f842
ansible-core@2.14.18
2.16.19rc1
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
ansible-core@2.15.3
2.16.19rc1
1
semaphoreui/semaphore:v2.9.645b50bc11833f
ansible-core@2.14.5
2.16.19rc1
1
semaphoreui/semaphore:v2.18.3e9260bfa8255
ansible-core@2.20.5
2.20.7rc1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
ansible-core@2.15.6
2.16.19rc1
1
ghcr.io/grycap/im:latest06a16d4f279f
ansible-core@2.15.13
2.16.19rc1
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
ansible-core@2.20.2
2.20.7rc1
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
ansible-core@2.15.8
2.16.19rc1
1
quay.io/kiali/kiali-operator:v2.31.0f837d8f25545
ansible-core@2.18.3
2.18.18rc1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.