#1149959 ansible: CVE-2026-87874

Package:
src:ansible
Source:
src:ansible
Submitter:
Salvatore Bonaccorso
Date:
2026-10-04 19:09:02 UTC
Severity:
normal
Tags:
#1149959#5
Date:
2026-10-04 19:06:49 UTC
From:
To:
Hi,

The following vulnerability was published for ansible.

CVE-2026-87874[0]:
| A flaw was found in the memcached cache plugin of the
| community.general Ansible collection. Although its documentation
| states that records are stored in JSON format, the plugin performs
| no explicit serialization and relies on python-memcached, which
| pickles values on write and unpickles them on read. Because
| memcached is unauthenticated and cache keys are predictable, an
| attacker able to reach a network-exposed or shared memcached
| instance can write a crafted pickle payload that is deserialized and
| executed on the Ansible controller when the poisoned fact cache is
| next read, leading to remote code execution.

At time of writing this bugreport only the Red Hat bugzilla entry was
known to me, can you research the upstream status and loop back here
the information?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-87874
https://www.cve.org/CVERecord?id=CVE-2026-87874
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2530995

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore