5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
CVE-2026-44546/GHSA-xh68-hfp5-5x5m affects the Python package daphne < 4.2.2. awx ships Django Channels 3.x stack which pins daphne >=3.0,<4; fixing this vulnerability would require migrating awx to the the Channels 4.x stack. Upstream awx tip of main has migrated to Channel 4.x (although not with the fixed version of daphne) but upstream maintainers will need to release those changes as a tagged version.
Status