Red Hat Product Errata RHSA-2026:42078 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:42078 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution (CVE-2026-11332) automation-controller: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (CVE-2026-8643) automation-controller: urllib3: Denial of Service due to excessive HTTP response decompression (CVE-2026-44432) automation-gateway: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization (CVE-2026-44492) automation-gateway: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name (CVE-2026-44496) automation-gateway: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution (CVE-2026-44494) automation-gateway: Axios: Information disclosure of proxy credentials via HTTP redirects (CVE-2026-44486) automation-gateway: Axios: Information disclosure of proxy credentials via redirect flows (CVE-2026-44487) automation-gateway: Axios: Denial of Service due to unenforced request and response size limits (CVE-2026-44488) automation-gateway: Axios: Information disclosure due to prototype pollution vulnerability (CVE-2026-44495) automation-gateway: fast-uri: URI authority bypass due to improper delimiter handling (CVE-2026-6322) automation-gateway: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget (CVE-2026-42044) automation-gateway: fast-uri: Path traversal vulnerability allows bypass of security policies (CVE-2026-6321) automation-gateway: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800) automation-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing (CVE-2026-12382) python3.12-pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport (CVE-2026-12701) receptor: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) receptor: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) receptor: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) receptor: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) receptor: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section. Solution For details on how to apply this update, refer to Ansible Automation Platform documentation. Affected Products Red Hat Ansible Automation Platform 2.5 for RHEL 9 x86_64 Red Hat Ansible Automation Platform 2.5 for RHEL 9 s390x Red Hat Ansible Automation Platform 2.5 for RHEL 9 ppc64le Red Hat Ansible Automation Platform 2.5 for RHEL 9 aarch64 Red Hat Ansible Automation Platform 2.5 for RHEL 8 x86_64 Red Hat Ansible Automation Platform 2.5 for RHEL 8 s390x Red Hat Ansible Automation Platform 2.5 for RHEL 8 ppc64le Red Hat Ansible Automation Platform 2.5 for RHEL 8 aarch64 Red Hat Ansible Inside 1.3 for RHEL 9 x86_64 Red Hat Ansible Inside 1.3 for RHEL 9 s390x Red Hat Ansible Inside 1.3 for RHEL 9 ppc64le Red Hat Ansible Inside 1.3 for RHEL 9 aarch64 Red Hat Ansible Inside 1.3 for RHEL 8 x86_64 Red Hat Ansible Inside 1.3 for RHEL 8 s390x Red Hat Ansible Inside 1.3 for RHEL 8 ppc64le Red Hat Ansible Inside 1.3 for RHEL 8 aarch64 Red Hat Ansible Developer 1.2 for RHEL 9 x86_64 Red Hat Ansible Developer 1.2 for RHEL 9 s390x Red Hat Ansible Developer 1.2 for RHEL 9 ppc64le Red Hat Ansible Developer 1.2 for RHEL 9 aarch64 Red Hat Ansible Developer 1.2 for RHEL 8 x86_64 Red Hat Ansible Developer 1.2 for RHEL 8 s390x Red Hat Ansible Developer 1.2 for RHEL 8 ppc64le Red Hat Ansible Developer 1.2 for RHEL 8 aarch64 Fixes BZ - 2453496 - CVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template imports BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2460927 - CVE-2026-8643 python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite BZ - 2461624 - CVE-2026-42044 axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget BZ - 2466582 - CVE-2026-6321 fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies BZ - 2466684 - CVE-2026-6322 fast-uri: fast-uri: URI authority bypass due to improper delimiter handling BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2477154 - CVE-2026-44432 urllib3: urllib3: Denial of Service due to excessive HTTP response decompression BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing BZ - 2480757 - CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass BZ - 2480761 - CVE-2026-25681 golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting BZ - 2485379 - CVE-2026-11332 ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution BZ - 2487937 - CVE-2026-44495 axios: Axios: Information disclosure due to prototype pollution vulnerability BZ - 2487938 - CVE-2026-44492 axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization BZ - 2487942 - CVE-2026-44494 axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution BZ - 2487943 - CVE-2026-44496 axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name BZ - 2487947 - CVE-2026-44486 axios: Axios: Information disclosure of proxy credentials via HTTP redirects BZ - 2487948 - CVE-2026-44487 axios: Axios: Information disclosure of proxy credentials via redirect flows BZ - 2487949 - CVE-2026-44488 axios: Axios: Denial of Service due to unenforced request and response size limits BZ - 2489126 - CVE-2026-12382 aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing BZ - 2490703 - CVE-2026-12701 pulpcore: pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport CVEs CVE-2026-4800 CVE-2026-6321 CVE-2026-6322 CVE-2026-8643 CVE-2026-11332 CVE-2026-12382 CVE-2026-12701 CVE-2026-25681 CVE-2026-27136 CVE-2026-32281 CVE-2026-33811 CVE-2026-39821 CVE-2026-42044 CVE-2026-44432 CVE-2026-44486 CVE-2026-44487 CVE-2026-44488 CVE-2026-44492 CVE-2026-44494 CVE-2026-44495 CVE-2026-44496 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Ansible Automation Platform 2.5 for RHEL 9 SRPM ansible-core-2.16.19-1.el9ap.src.rpm SHA-256: 3796ccb3238218b6b496ddb85c01e139cc1ccc2632677be3671fc39223c1aa7a automation-controller-4.6.30-2.el9ap.src.rpm SHA-256: 4565bac1ee15744dcbe16e4f79931cbdd59df3196e7fe17e2c7e155923e44779 automation-eda-controller-1.1.20-1.el9ap.src.rpm SHA-256: 52c7539de3459a24b3a089008ae61830338a9fd582c67bdc80eb6981366d5e3a automation-gateway-2.5.20260715-1.el9ap.src.rpm SHA-256: 8a988434c7c4453f1e910e0d488519293c3467c1a137497c538a34f73d2dfd5a automation-hub-4.10.16-1.el9ap.src.rpm SHA-256: f1044cbcf90342bd06163896bc727b55a45574df72facb3c5e7d7b2ded195a70 python3.12-galaxy-ng-4.10.16-1.el9ap.src.rpm SHA-256: 3644f70f2db326a8b3f987590de58e6adaa557473506546bba2a8a7abad33b55 python3.12-gitpython-3.1.50-1.el9ap.src.rpm SHA-256: c3e55879a30f72132de7ba481edd8ac2b3d985f82b27bcaef53b38de90a7120e python3.12-pulp-ansible-0.25.6-1.el9ap.src.rpm SHA-256: 61499d1d2ebd7bb6bb546e5bb40fbc47e9ccbc5311cbd8ea78f4b4faaa3a6a61 python3.12-pulp-container-2.19.12-1.el9ap.src.rpm SHA-256: 3c5f7934e1b9454934c04b7f382345ddca6583acaa6c0ce81215196eeca7a556 python3.12-pulpcore-3.49.63-2.el9ap.src.rpm SHA-256: 03176add14b9d9ac6c5e9cafdea79f56ce813a0f3e4a92fd877cc90493837d7d python3.12-pyjwt-2.13.0-1.el9ap.src.rpm SHA-256: b1900f9d95f094701e32eee35fbea447eb21bee4120892222ee8ef1903b77845 python3.12-pysequoia-0.1.34-1.el9ap.src.rpm SHA-256: 0cd71561365c3506eae322e950d1784da1d043d36596fc32040abd625f19581a python3.12-urllib3-2.7.0-1.el9ap.src.rpm SHA-256: 345f3b838f1f6552f90f5775c4330834e3a67f7b4b814ac583b5e85dd41ee061 receptor-1.6.6-1.el9ap.src.rpm SHA-256: c91c
This Red Hat security advisory addresses multiple vulnerabilities in Ansible Automation Platform 2.5, including an argument injection in ansible-galaxy (CVE-2026-11332, CVSS 7.8 HIGH) leading to arbitrary code execution and a path traversal in automation-controller (CVE-2026-8643, CVSS 5.5 MEDIUM) allowing arbitrary file overwrite. The advisory also resolves several high-severity issues in dependent components, such as a denial of service in urllib3 (CVE-2026-44432, CVSS 7.5 HIGH) affecting versions 2.6.0 through 2.6.9, which is fixed in urllib3 2.7.0, and multiple vulnerabilities in Axios and other libraries within the automation-gateway component.