{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11820.json"
      }
    ],
    "title": "community.general: community.general nexmo — API credentials exposed in GET URL query string[SECURITY] community.general nexmo — API credentials exposed in GET URL query string",
    "tracking": {
      "current_release_date": "2026-08-17T16:12:58+00:00",
      "generator": {
        "date": "2026-08-17T16:12:58+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.16"
        }
      },
      "id": "CVE-2026-11820",
      "initial_release_date": "2026-06-15T01:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-06-15T01:00:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-26T00:01:40+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-17T16:12:58+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 10",
                "product": {
                  "name": "Red Hat Enterprise Linux 10",
                  "product_id": "red_hat_enterprise_linux_10",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:10"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 10"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 8",
                "product": {
                  "name": "Red Hat Enterprise Linux 8",
                  "product_id": "red_hat_enterprise_linux_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 9",
                "product": {
                  "name": "Red Hat Enterprise Linux 9",
                  "product_id": "red_hat_enterprise_linux_9",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:9"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 9"
          },
          {
            "category": "product_version",
            "name": "rhel-system-roles.src",
            "product": {
              "name": "rhel-system-roles.src",
              "product_id": "rhel-system-roles.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rhel-system-roles?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhc-worker-playbook.src",
            "product": {
              "name": "rhc-worker-playbook.src",
              "product_id": "rhc-worker-playbook.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rhc-worker-playbook?arch=src"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhel-system-roles.src as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:rhel-system-roles.src"
        },
        "product_reference": "rhel-system-roles.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhc-worker-playbook.src as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:rhc-worker-playbook.src"
        },
        "product_reference": "rhc-worker-playbook.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhel-system-roles.src as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:rhel-system-roles.src"
        },
        "product_reference": "rhel-system-roles.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhel-system-roles.src as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:rhel-system-roles.src"
        },
        "product_reference": "rhel-system-roles.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Bipin Saud"
          ],
          "organization": "https://www.linkedin.com/in/bipinsaud/"
        }
      ],
      "cve": "CVE-2026-11820",
      "cwe": {
        "id": "CWE-532",
        "name": "Insertion of Sensitive Information into Log File"
      },
      "discovery_date": "2026-06-15T18:38:43.346000+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2488970"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the community.general Ansible collection's nexmo module.\nThe module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding\nAPI credentials (api_key and api_secret) into URL query parameters and\nsending them via GET requests. This causes credentials to be exposed in web\nserver access logs, proxy logs, HTTP Referer headers, and network monitoring\ntools, despite the Ansible argument specification marking these parameters\nas no_log. An attacker with access to any of these logging or monitoring\npoints can obtain the full API credentials and gain unauthorized access to\nthe victim's Vonage/Nexmo account.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "community.general: community.general nexmo — API credentials exposed in GET URL query string[SECURITY] community.general nexmo — API credentials exposed in GET URL query string",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "Code Flaw initial found in community.general 13.0.0, however, the same code logic is found in older versions going back at least to 8.3.\n\nThis flaw affects the community.general Ansible collection's nexmo module in\nall versions prior to its removal in 9.0.0. Red Hat ships\nansible-collection-community-general in several product streams (EPEL, Fedora,\nOpenStack). The vulnerability exposes Vonage/Nexmo API credentials in HTTP\nrequest URLs, making them available in server logs and network monitoring.\nThe nexmo module is deprecated upstream and the recommended remediation is to\nstop using it in favor of direct API calls via the uri module.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "under_investigation": [
          "red_hat_enterprise_linux_10:rhel-system-roles.src",
          "red_hat_enterprise_linux_8:rhc-worker-playbook.src",
          "red_hat_enterprise_linux_8:rhel-system-roles.src",
          "red_hat_enterprise_linux_9:rhel-system-roles.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-11820"
        },
        {
          "category": "external",
          "summary": "RHBZ#2488970",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488970"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-11820",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-11820"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-11820",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11820"
        }
      ],
      "release_date": "2026-06-15T01:00:00+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "red_hat_enterprise_linux_10:rhel-system-roles.src",
            "red_hat_enterprise_linux_8:rhc-worker-playbook.src",
            "red_hat_enterprise_linux_8:rhel-system-roles.src",
            "red_hat_enterprise_linux_9:rhel-system-roles.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "red_hat_enterprise_linux_10:rhel-system-roles.src",
            "red_hat_enterprise_linux_8:rhc-worker-playbook.src",
            "red_hat_enterprise_linux_8:rhel-system-roles.src",
            "red_hat_enterprise_linux_9:rhel-system-roles.src"
          ]
        }
      ],
      "title": "community.general: community.general nexmo — API credentials exposed in GET URL query string[SECURITY] community.general nexmo — API credentials exposed in GET URL query string"
    }
  ]
}