Red Hat Product Errata RHSA-2026:42079 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:42079 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution (CVE-2026-11332) automation-controller: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (CVE-2026-8643) automation-controller: urllib3: Denial of Service due to excessive HTTP response decompression (CVE-2026-44432) automation-platform-ui: fast-uri: Path traversal vulnerability allows bypass of security policies (CVE-2026-6321) python3.12-pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport (CVE-2026-12701) receptor: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) receptor: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) receptor: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) receptor: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) receptor: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) receptor: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) For details about this release, refer to the release notes listed in the References section. Solution For details on how to apply this update, refer to Ansible Automation Platform documentation. Affected Products Red Hat Ansible Automation Platform 2.6 for RHEL 10 x86_64 Red Hat Ansible Automation Platform 2.6 for RHEL 10 s390x Red Hat Ansible Automation Platform 2.6 for RHEL 10 ppc64le Red Hat Ansible Automation Platform 2.6 for RHEL 10 aarch64 Red Hat Ansible Automation Platform 2.6 for RHEL 9 x86_64 Red Hat Ansible Automation Platform 2.6 for RHEL 9 s390x Red Hat Ansible Automation Platform 2.6 for RHEL 9 ppc64le Red Hat Ansible Automation Platform 2.6 for RHEL 9 aarch64 Red Hat Ansible Inside 1.4 x86_64 Red Hat Ansible Inside 1.4 s390x Red Hat Ansible Inside 1.4 ppc64le Red Hat Ansible Inside 1.4 aarch64 Red Hat Ansible Developer 1.3 for RHEL 10 x86_64 Red Hat Ansible Developer 1.3 for RHEL 10 s390x Red Hat Ansible Developer 1.3 for RHEL 10 ppc64le Red Hat Ansible Developer 1.3 for RHEL 10 aarch64 Red Hat Ansible Developer 1.3 for RHEL 9 x86_64 Red Hat Ansible Developer 1.3 for RHEL 9 s390x Red Hat Ansible Developer 1.3 for RHEL 9 ppc64le Red Hat Ansible Developer 1.3 for RHEL 9 aarch64 Fixes BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2460927 - CVE-2026-8643 python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite BZ - 2466582 - CVE-2026-6321 fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2477154 - CVE-2026-44432 urllib3: urllib3: Denial of Service due to excessive HTTP response decompression BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing BZ - 2480757 - CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass BZ - 2480761 - CVE-2026-25681 golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries BZ - 2485379 - CVE-2026-11332 ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution BZ - 2490703 - CVE-2026-12701 pulpcore: pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport CVEs CVE-2026-6321 CVE-2026-8643 CVE-2026-11332 CVE-2026-12701 CVE-2026-25681 CVE-2026-27136 CVE-2026-27145 CVE-2026-32281 CVE-2026-33811 CVE-2026-39821 CVE-2026-44432 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Ansible Automation Platform 2.6 for RHEL 10 SRPM ansible-core-2.16.19-1.el10ap.src.rpm SHA-256: 14c86bfefe2c767397fae7b2651dbb156c5b6d24f08aa13f1bfc4757714057ed ansible-creator-26.6.1-1.el10ap.src.rpm SHA-256: 5f5311accce1d31af00fbcca58539ce224a2654f16b367ba1233803fcab6bfc3 ansible-dev-environment-26.6.1-1.el10ap.src.rpm SHA-256: e3a05521e421655e286c3a772616c6b885672f0befe64e411db3be34be45cc73 ansible-dev-tools-26.7.1-1.el10ap.src.rpm SHA-256: 3e7b9fb8a8743a82858d7ccc546f2fe18e3c46df96396da413c2b3bcc7414051 ansible-lint-26.6.0-1.el10ap.src.rpm SHA-256: 2e0c92feeca539899fef8a2fb5e281940149df94f74daac534d53f0b6f590ee4 ansible-navigator-26.6.0-1.el10ap.src.rpm SHA-256: eaedc95545299efee40448057a3f2de260616040ccd271c903836977d78b6568 ansible-sign-0.1.6-1.el10ap.src.rpm SHA-256: cb217ff4a29c13c739fdf2fd5c21e7b39d18d6a0f0ba45bd3c3e46da3a497855 molecule-26.6.0-1.el10ap.src.rpm SHA-256: 3c31cbc406724685e664f1549d5924b47dd41787f3766bb5abb3b9106cc1faa1 python-pytest-ansible-26.6.0-1.el10ap.src.rpm SHA-256: 2adef8e3ff8c574ed11c9d24194c056679d5b29958f82f6f0d1620edc3051564 python-tox-ansible-26.6.1-1.el10ap.src.rpm SHA-256: a36ab5df60a2d04d40f8bd40a9f2b441f293ebb4fc82330ab060bbd6733a8d8d receptor-1.6.6-1.el10ap.src.rpm SHA-256: fad643f3a456ee5ed38367ba92f3456ff8b574e0a480ede5020accdda7377e00 x86_64 ansible-core-2.16.19-1.el10ap.noarch.rpm SHA-256: 225ec1679698fe8d09b53e81cf80dd45581fcfd06239cc35ce02d37036b2a515 ansible-creator-26.6.1-1.el10ap.noarch.rpm SHA-256: 9cc6e0ab6e7cc477b1da48ecc63b129a0b1270c38b7b1b760ed2978024ba0b4c ansible-dev-environment-26.6.1-1.el10ap.noarch.rpm SHA-256: cc6597fa7d3a5857db92dac783358eac74d4e4352c88f60c4343253661b443db ansible-dev-tools+server-26.7.1-1.el10ap.noarch.rpm SHA-256: 68bba58f6f1b572ce0f9d432473de112135023a30a01a58d1699343b668650f0 ansible-dev-tools-26.7.1-1.el10ap.noarch.rpm SHA-256: 60af03599c022bf0b11d287bd8f393d311f6988d7efec425a2157c5d326f306e ansible-lint-26.6.0-1.el10ap.noarch.rpm SHA-256: f2cbbd7ba32b6d733744cd28cde6c4333ec47435a7f6ebae2f236acde8755c9b ansible-navigator-26.6.0-1.el10ap.noarch.rpm SHA-256: eb681939e8bc087a20c3c8566b3d947c3ec9e19cb2edfffe835d4fd87baa09ee ansible-sign-0.1.6-1.el10ap.noarch.rpm SHA-256: 5f3da6aadefdbd0f30434f6bbf2a8a6b9c23edf172676a1198d45803a6ca4c06 molecule-26.6.0-1.el10ap.noarch.rpm SHA-256: 5d2ba7faf4dc161c4d5953a659a363c9e392e4da5f57aeeefe296fac94140848 python3-pytest-ansible-26.6.0-1.el10ap.noarch.rpm SHA-256: 8a20d4b80d8a449365c9506e4fc58f626f45a81f903781d36eb47d3197f8e679 python3-tox-ansible-26.6.1-1.el10ap.noarch.rpm SHA-256: 53c0e217974ccc59f44e83ec6780520c4eec5977b563ceb4abad58fd562835da receptor-1.6.6-1.el10ap.x86_64.rpm SHA-256: f4e67211a779a8ff96214d717853baecb77438cc243a8ffd0753bdb258901ab9 receptor-debuginfo-1.6.6-1.el10ap.x86_64.rpm SHA-256: 3919fcaa28a0bec81690e86e8243ea60c050908726e5a9bd0f11ac29a37ab6c2 receptor-debugsource-1.6.6-1.el10ap.x86_64.rpm SHA-256: 18513df1fc77095408d6c1674e16d8ca672ba33be0ff4c18e932fbb0b2fe13c1 receptorctl-1.6.6-1.el10ap.noarch.rpm SHA-256: 65b400c4f916aba9a42b6db366669117c3d93fef9f11f7c93b6d3ef37fe2aa5f s390x ansible-core-2.16.19-1.el10ap.noarch.rpm SHA-256: 225ec1679698fe8d09b53e81cf80dd45581fcfd06239cc35ce02d37036b2a515 ansible-creator-26.6.1-1.el10ap.noarch.rpm SHA-256: 9cc6e0ab6e7cc477b1da48ecc63b129a0b1270c38b7b1b760ed2978024ba0b4c ansible-dev-environment-26.6.1-1.el10ap.noarch.rpm SHA-256: cc6597fa7d3a5857db92dac783358eac74d4e4352c88f60c4343253661b443db ansible-dev-tools+server-26.7.1-1.el10ap.noarch.rpm SHA-256: 68bba58f6f1b572ce0f9d432473de112135023a30a01a58d1699343b668650f0 ansible-dev-tools-26.7.1-1.el10ap.noarch.rpm SHA-256: 60af03599c022bf0b11d287bd8f393d311f6988d7efec425a2157c5d326f306e ansible-lint-26.6.0-1.el10ap.noarch.rpm SHA-256: f2cbbd7ba32b6d733744cd28cde6c4333ec47435a7f6ebae2f236acde8755c9b ansible-navigator-26.6.0-1.el10ap.noarch.rpm SHA-256: eb681939e8bc087a20c3c8566b3d947c3ec9e19cb2edfffe835d4fd87baa09ee ansible-sign-0.1.6-1.el10ap.noarch.rpm SHA-256: 5f3da6aadefdbd0f30434f6bbf2a8a6b9c23edf172676a1198d45803a6ca4c06 molecule-26.6.0-1.el10ap.noarch.rpm SHA-256: 5d2ba7faf4dc161c4d5953a659a363c9e392e4da5f57aeeefe296fac94140848 python3-pytest-ansible-26.6.0-1.el10ap.noarch.rpm SHA-256: 8a20d4b80d8a449365c9506e4fc58f626f45a81f903781d36eb47d3197f8e679 python3-tox-ansible-26.6.1-1.el10ap.noarch.rpm SHA-256: 53c0e217974ccc59f44e83ec6780520c4eec5977b563ceb4
This Red Hat Ansible Automation Platform 2.6 update addresses multiple Important-severity vulnerabilities, including an argument injection flaw in ansible-galaxy (CVE-2026-11332, CVSS 7.8 HIGH) leading to arbitrary code execution and a path traversal in automation-controller via malicious pip wheel names (CVE-2026-8643, CVSS 5.5 MEDIUM). The advisory includes fixes for components like urllib3 (CVE-2026-44432, CVSS 7.5 HIGH), where versions 2.6.0 through 2.6.x are affected and should be updated to 2.7.0, and for pip, where versions prior to 26.1.2 are affected. IT professionals should apply the platform update per Red Hat documentation.