Hi,
The following vulnerability was published for ansible.
CVE-2026-87874[0]:
| A flaw was found in the memcached cache plugin of the
| community.general Ansible collection. Although its documentation
| states that records are stored in JSON format, the plugin performs
| no explicit serialization and relies on python-memcached, which
| pickles values on write and unpickles them on read. Because
| memcached is unauthenticated and cache keys are predictable, an
| attacker able to reach a network-exposed or shared memcached
| instance can write a crafted pickle payload that is deserialized and
| executed on the Ansible controller when the poisoned fact cache is
| next read, leading to remote code execution.
At time of writing this bugreport only the Red Hat bugzilla entry was
known to me, can you research the upstream status and loop back here
the information?
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-87874
https://www.cve.org/CVERecord?id=CVE-2026-87874
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2530995
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore