Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:34160: Important: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update

This Red Hat security advisory addresses multiple Important-severity vulnerabilities in Ansible Automation Platform 2.6, including prototype pollution leading to header injection and information disclosure in Axios (CVE-2026-44495, CVSS 7.0; CVE-2026-42035), a URI authority bypass in fast-uri (CVE-2026-6322, CVSS 7.5), and arbitrary code execution via Server-Side Template Injection in Dynaconf (CVE-2026-33154). For the specific component vulnerabilities, Axios versions 1.7.0 through 1.15.x are affected and must be upgraded to version 1.16.0, while fast-uri versions prior to 3.1.2 require an update to version 3.1.2. The update is available for Ansible Automation Platform 2.6 on RHEL 9 across multiple architectures.
Read Full Article →

Red Hat Product Errata RHSA-2026:34160 - Security Advisory Issued: 2026-07-01 Updated: 2026-07-01 RHSA-2026:34160 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 2.6 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): automation-platform-ui: Axios: Denial of Service due to unenforced request and response size limits (CVE-2026-44488) automation-platform-ui: Axios: Information disclosure due to prototype pollution vulnerability (CVE-2026-44495) automation-platform-ui: fast-uri: URI authority bypass due to improper delimiter handling (CVE-2026-6322) automation-platform-ui: Axios: Arbitrary HTTP header injection via prototype pollution (CVE-2026-42035) automation-platform-ui: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization (CVE-2026-41240) automation-platform-ui: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors (CVE-2026-44293) python3.12-pyjwt: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526) automation-controller: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154) python3.12-urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers (CVE-2026-44431) python3.12-urllib3: Denial of Service due to excessive HTTP response decompression (CVE-2026-44432) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, refer to Ansible Automation Platform documentation. Affected Products Red Hat Ansible Automation Platform 2.6 for RHEL 9 x86_64 Red Hat Ansible Automation Platform 2.6 for RHEL 9 s390x Red Hat Ansible Automation Platform 2.6 for RHEL 9 ppc64le Red Hat Ansible Automation Platform 2.6 for RHEL 9 aarch64 Red Hat Ansible Developer 1.3 for RHEL 9 x86_64 Red Hat Ansible Developer 1.3 for RHEL 9 s390x Red Hat Ansible Developer 1.3 for RHEL 9 ppc64le Red Hat Ansible Developer 1.3 for RHEL 9 aarch64 Fixes BZ - 2449774 - CVE-2026-33154 dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection BZ - 2461147 - CVE-2026-41240 DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization BZ - 2461606 - CVE-2026-42035 axios: Axios: Arbitrary HTTP header injection via prototype pollution BZ - 2466684 - CVE-2026-6322 fast-uri: fast-uri: URI authority bypass due to improper delimiter handling BZ - 2477104 - CVE-2026-44293 protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors BZ - 2477154 - CVE-2026-44432 urllib3: urllib3: Denial of Service due to excessive HTTP response decompression BZ - 2477167 - CVE-2026-44431 urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers BZ - 2482734 - CVE-2026-48526 python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens BZ - 2487937 - CVE-2026-44495 axios: Axios: Information disclosure due to prototype pollution vulnerability BZ - 2487949 - CVE-2026-44488 axios: Axios: Denial of Service due to unenforced request and response size limits CVEs CVE-2026-6322 CVE-2026-33154 CVE-2026-41240 CVE-2026-42035 CVE-2026-44293 CVE-2026-44431 CVE-2026-44432 CVE-2026-44488 CVE-2026-44495 CVE-2026-48526 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Ansible Automation Platform 2.6 for RHEL 9 SRPM automation-controller-4.7.13-2.el9ap.src.rpm SHA-256: 1268eede9b2937467396490a05eca54f54357470c7e2c4f6ef88380cd95cdc55 automation-eda-controller-1.2.9-3.el9ap.src.rpm SHA-256: 61d939de9077562c6b92f555832f4cd093bebde351973c8242ea597c93f9a9cb automation-gateway-2.6.20260701-1.el9ap.src.rpm SHA-256: c4ea4f41588562171190091e9f7e5610c523f2b4ecb6ac57a0439a8bce8be6d8 automation-hub-4.11.10-1.el9ap.src.rpm SHA-256: 770af6fb60d77b68bdc6556448500759e9219683230d1c3f89a76a0b497c4a1b automation-platform-ui-2.6.10-1.el9ap.src.rpm SHA-256: fbc2aa132e3afe635904bcff46f78dc9d036f2dcc479e8e108cefe8d91650d9e python3.12-django-ansible-base-2.6.20260701-2.el9ap.src.rpm SHA-256: c3076a5d756b0a1bfd9dc013932da9e65e50891fdef96423fed9dce3f60b4342 python3.12-galaxy-ng-4.11.10-1.el9ap.src.rpm SHA-256: 9056e17530ccefdb2b8856ab7cb0cc86d75823a0f873037e1ba1e596673ed475 python3.12-pulp-container-2.19.12-1.el9ap.src.rpm SHA-256: 3c5f7934e1b9454934c04b7f382345ddca6583acaa6c0ce81215196eeca7a556 python3.12-pyjwt-2.13.0-1.el9ap.src.rpm SHA-256: b1900f9d95f094701e32eee35fbea447eb21bee4120892222ee8ef1903b77845 python3.12-pysequoia-0.1.34-1.el9ap.src.rpm SHA-256: 0cd71561365c3506eae322e950d1784da1d043d36596fc32040abd625f19581a python3.12-urllib3-2.7.0-1.el9ap.src.rpm SHA-256: 345f3b838f1f6552f90f5775c4330834e3a67f7b4b814ac583b5e85dd41ee061 x86_64 automation-controller-4.7.13-2.el9ap.x86_64.rpm SHA-256: ca2fee84862f11cf1c592abcb3af2130de69ef95d2d8ef1825c7d717c693d76f automation-controller-cli-4.7.13-2.el9ap.noarch.rpm SHA-256: ef6c68b5b34dc7f84275ba805c2f813fd8fd323f38eee3f7bbd1bce881306c5b automation-controller-server-4.7.13-2.el9ap.noarch.rpm SHA-256: 685741a04b640e7441c0e14dd16d91132ac9248a086cdddaacd5bf05d422805d automation-controller-ui-4.7.13-2.el9ap.noarch.rpm SHA-256: f95af34c1674d46a8ff510e89b01c183239b862592901e2143516dba16bdfc80 automation-controller-venv-tower-4.7.13-2.el9ap.x86_64.rpm SHA-256: 9e6a18f5641742ce5c7619e9ff4965389081ff78a1ba3b473f9a26b15d807370 automation-eda-controller-1.2.9-3.el9ap.noarch.rpm SHA-256: ff3cb29e4e0f763fc8b1973a07828503423773ffc6c9a86f549d049058d2af6a automation-eda-controller-base-1.2.9-3.el9ap.noarch.rpm SHA-256: 14f3252e7c0b948f30286e719fd945802eed3ee0302d8c3859f8cb4ec1a1cd09 automation-eda-controller-base-services-1.2.9-3.el9ap.noarch.rpm SHA-256: 6e10fff3566034cc272876b38a0b3f00011f54423bfedf9d719bb322d2431abd automation-eda-controller-event-stream-services-1.2.9-3.el9ap.noarch.rpm SHA-256: c8b24e8b7fba6dd3b774adc4590752448310eea9cc04700c795a84832bec2a40 automation-eda-controller-worker-services-1.2.9-3.el9ap.noarch.rpm SHA-256: 1a57127f10dacbcb64a5f7df5f8067da69ad1dde406e96fb2f5cd7e4784635ae automation-gateway-2.6.20260701-1.el9ap.noarch.rpm SHA-256: cfcae55aa0dbad9618fc95f2f4a4c03cfa4af1779359146abc7bef0da1e1f102 automation-gateway-config-2.6.20260701-1.el9ap.noarch.rpm SHA-256: b20cc57ea143d76305e274732235e102de7a677d3297e8c554949b6dd6034f84 automation-gateway-server-2.6.20260701-1.el9ap.noarch.rpm SHA-256: 5d6994dc77b25c03713588cb4efdc087febbc9f5b209dfd5aebd8c99b58a466f automation-hub-4.11.10-1.el9ap.noarch.rpm SHA-256: 9814f866176bd434341460f35f379959288d86aec992b2618243380533e0ec89 automation-platform-ui-2.6.10-1.el9ap.noarch.rpm SHA-256: ff7df45048f4d4387bc41d2b40335266a174085d1e01c36d2c2aa7f8d1972dfd python3.12-django-ansible-base+activitystream-2.6.20260701-2.el9ap.noarch.rpm SHA-256: f131230fbde5231b73bf2b6c51057093d89fb4c9daf4098e187899a2d01308de python3.12-django-ansible-base+api_documentation-2.6.20260701-2.el9ap.noarch.rpm SHA-256: 71e884388f25a49e0fd83384d439e6ac984ad58190783209986d8d2ea9bb406e python3.12-django-ansible-base+authentication-2.6.20260701-2.el9ap.noarch.rpm SHA-256: d815425d4ed79372d40b6650eb009b864bd023942de25e633227554a26f61cdd python3.12-django-ansible-base+channel_auth-2.6.20260701-2.el9ap.noarch.rpm SHA-256: c0d246c465bb5458f462599780532f59ee5117e6aaae96aff677330e7c2db079 python3.12-django-ansible-base+feature_flags-2.6.20260701-2.el9ap.noarch.rpm SHA-256: 0ac543a83a8eead839912bb4b586693abfce370038a670a3586d0299f541f37f python3.12-django-ansible-base+jwt_consumer-2.6.20260701-2.el9ap.noarch.rpm SHA-256: f9fd235d217702f42460b24ea45340ce1aff81df91a28617620019dd894f67c8 python3.12-django-ansible-base+oauth2_provider-2.6.20260701-2.el9ap.noarch.rpm SHA-256: b1fe5340b3b8bb8f63b4a2422a3452b8cb44cad466fee01fa71b380ccd797030 python3.12-django-ansible-base+rbac-2.6.20260701-2.el9ap.noarch.rpm SHA-256: c721c1ac9746b3db3d349c011222cf37b73a2ebd1fd8be2aadd92e079753600f python3.12-django-ansible-base+redis_client-2.6.20260701-2.el9ap.noarch.rpm SHA-256: b3ad95e770cd918895972801790d92ab603a752b4ef9c94462dc64985c4842fb python3.12-django-ansible-base+resource_registry-2.6.20260701-2.el9ap.noarch.rpm SHA-256: 613d960efb6e529d2d84062d75b2eafd3da9713ee2ad9414c01e0398c84d875b python3.12-django-ansible-base+rest_filters-2.6.20260701-2.el9ap.noarch.rpm SHA-256: 941367c185c27b38c9a07b1cba30ef18261fcfcff479450bbd7500c9319a0198 python3.12-django-ansible-base-2.6.20260701-2.el9ap.noarch.rpm SHA-256: 669476149b3d0788b9eccc05feedf92dd0f107caf0fbfd8934c05376a7b16f31 python3.12-galaxy-ng-4.11.10-1.el

Share this article