Fedora Account System
Red Hat Associate
Red Hat Customer
AUTH_TOKEN in pulp_ansible/app/downloaders.py is a module global. TokenAuthHttpDownloader.get_or_update_token() returns that global to any downloader in the process. It is not stored per remote or per token URL. The refresh path runs only when the remote has both token and auth_url. A worker that has already refreshed one remote's token sends that access token as the bearer for a later remote. The collection remote token field is write-only. Introduced by 57f5775b, first release 0.6.0. It has same root cause as reported pulp_container finding (CVE-2026-103868). This is a separate CVE from the pulp-container, as it has different codebase, and independently fixable.