Debian Package Tracker
Register | Log in
Subscribe

ansible-core

Configuration management, deployment, and task execution system

Choose email to subscribe with

general
  • source: ansible-core (main)
  • version: 2.21.2-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Lee Garrett [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 2.14.18-0+deb12u2
  • stable: 2.19.4-0+deb13u1
  • testing: 2.21.2-1
  • unstable: 2.21.2-1
versioned links
  • 2.14.18-0+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.19.4-0+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.21.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ansible-core
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 1:55:44
    Last run: 2026-07-15T05:25:10.000Z
    Previous status: unknown

  • testing: pass (log)
    The tests ran in 1:57:10
    Last run: 2026-07-15T05:28:24.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 1:29:04
    Last run: 2026-07-15T21:09:28.000Z
    Previous status: unknown

Created: 2026-06-24 Last update: 2026-08-10 03:31
A new upstream version is available: 2.21.3rc1 high
A new upstream version 2.21.3rc1 is available, you should consider packaging it.
Created: 2026-08-05 Last update: 2026-08-10 03:30
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-16493: A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection source URI containing git argument injection payloads can achieve arbitrary command execution when a user runs 'ansible-galaxy collection install' with the malicious source. This is an incomplete fix for CVE-2026-11332, which hardened the role install path but missed the equivalent collection install code path.
Created: 2026-07-21 Last update: 2026-08-09 01:33
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-16493: A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection source URI containing git argument injection payloads can achieve arbitrary command execution when a user runs 'ansible-galaxy collection install' with the malicious source. This is an incomplete fix for CVE-2026-11332, which hardened the role install path but missed the equivalent collection install code path.
Created: 2026-07-21 Last update: 2026-08-09 01:33
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-16493: A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection source URI containing git argument injection payloads can achieve arbitrary command execution when a user runs 'ansible-galaxy collection install' with the malicious source. This is an incomplete fix for CVE-2026-11332, which hardened the role install path but missed the equivalent collection install code path.
1 issue postponed or untriaged:
  • CVE-2026-11332: (postponed; to be fixed through a stable update) A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
Created: 2026-06-06 Last update: 2026-08-09 01:33
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-16493: (needs triaging) A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection source URI containing git argument injection payloads can achieve arbitrary command execution when a user runs 'ansible-galaxy collection install' with the malicious source. This is an incomplete fix for CVE-2026-11332, which hardened the role install path but missed the equivalent collection install code path.

You can find information about how to handle this issue in the security team's documentation.

1 issue that should be fixed with the next stable update:
  • CVE-2026-11332: A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
Created: 2026-07-21 Last update: 2026-08-09 01:33
news
[rss feed]
  • [2026-07-25] ansible-core 2.21.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-19] Accepted ansible-core 2.21.2-1 (source) into unstable (Lee Garrett)
  • [2026-07-04] ansible-core 2.21.1~rc1-2 MIGRATED to testing (Debian testing watch)
  • [2026-06-29] Accepted ansible-core 2.21.1~rc1-2 (source) into unstable (Alexandre Detiste)
  • [2026-06-24] ansible-core 2.21.1~rc1-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-18] Accepted ansible-core 2.21.1~rc1-1 (source) into unstable (Lee Garrett)
  • [2026-05-22] Accepted ansible-core 2.21.0-1 (source) into unstable (Lee Garrett)
  • [2026-03-18] ansible-core 2.20.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-13] Accepted ansible-core 2.20.3-1 (source) into unstable (Lee Garrett)
  • [2026-01-24] ansible-core 2.20.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-19] Accepted ansible-core 2.20.1-1 (source) into unstable (Lee Garrett)
  • [2025-11-11] ansible-core 2.19.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-08] Accepted ansible-core 2.19.4-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Lee Garrett)
  • [2025-11-05] Accepted ansible-core 2.19.4-1 (source) into unstable (Lee Garrett)
  • [2025-10-28] ansible-core 2.19.3-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-22] Accepted ansible-core 2.19.3-2 (source) into unstable (Colin Watson)
  • [2025-10-19] Accepted ansible-core 2.19.1-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Lee Garrett)
  • [2025-10-12] ansible-core 2.19.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-07] Accepted ansible-core 2.19.3-1 (source) into unstable (Lee Garrett)
  • [2025-09-16] ansible-core 2.19.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-10] Accepted ansible-core 2.19.2-1 (source) into unstable (Lee Garrett)
  • [2025-09-02] ansible-core 2.19.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-26] Accepted ansible-core 2.19.1-1 (source) into unstable (Lee Garrett)
  • [2025-08-13] ansible-core 2.19.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-07-22] Accepted ansible-core 2.19.0-1 (source) into unstable (Lee Garrett)
  • [2025-07-09] Accepted ansible-core 2.19.0~rc2-1 (source) into unstable (Lee Garrett)
  • [2025-07-03] ansible-core 2.19.0~beta6-1 MIGRATED to testing (Debian testing watch)
  • [2025-06-12] Accepted ansible-core 2.19.0~beta6-1 (source) into unstable (Lee Garrett)
  • [2025-06-05] ansible-core 2.19.0~beta4-1 MIGRATED to testing (Debian testing watch)
  • [2025-06-04] Accepted ansible-core 2.19.0~beta5-1 (source) into unstable (Lee Garrett)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.21.1~rc1-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing