- What: Security and bug fix update for Red Hat Ansible Automation Platform 2.6
- Impact: Enterprise IT automation systems affected
Red Hat Product Errata RHSA-2026:59136 - Security Advisory Issued: 2026-08-24 Updated: 2026-08-24 RHSA-2026:59136 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 2.6 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): automation-controller: notification backends allow SSRF and credential leakage (CVE-2026-71366) automation-controller: webhook status callback SSRF leaks the Git PAT (CVE-2026-71365) automation-controller: project archive extraction allows path traversal file writes (CVE-2026-71364) automation-controller: AIO HTTP: HTTP Request Smuggling via WebSocket Upgrade (CVE-2026-69243) automation-controller: AIO HTTP: Denial of Service via malformed HTTP responses (CVE-2026-69244) automation-controller: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886) automation-controller: path traversal via YAML !include directive (CVE-2026-52902) automation-controller: AIO HTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993) automation-controller: daphne: Denial of Service via excessive WebSocket message size (CVE-2026-44545) automation-controller: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373) automation-platform-ui: form-data: Form field override via CRLF injection (CVE-2026-12143) automation-platform-ui: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705) python-django: Remote code execution via GeoDjango spatial lookups (CVE-2026-15307) python3.12-aio http: HTTP Request Smuggling via WebSocket Upgrade (CVE-2026-69243) python3.12-aio http: Denial of Service via malformed HTTP responses (CVE-2026-69244) python3.12-django: Remote code execution via GeoDjango spatial lookups (CVE-2026-15307) python3.12-gitpython: Command Injection via Git option prefix abbreviation (CVE-2026-67325) python3.12-gitpython: Arbitrary Code Execution via Joined Short Options Bypass (CVE-2026-67324) python3.12-gitpython: Arbitrary code execution via command injection due to unguarded Git options (CVE-2026-67323) python3.12-gitpython: Environment variable exfiltration via attacker-controlled clone URL (CVE-2026-67322) python3.12-gitpython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section. Solution For details on how to apply this update, refer to Ansible Automation Platform documentation. Affected Products Red Hat Ansible Automation Platform 2.6 for RHEL 10 x86_64 Red Hat Ansible Automation Platform 2.6 for RHEL 10 s390x Red Hat Ansible Automation Platform 2.6 for RHEL 10 ppc64le Red Hat Ansible Automation Platform 2.6 for RHEL 10 aarch64 Red Hat Ansible Automation Platform 2.6 for RHEL 9 x86_64 Red Hat Ansible Automation Platform 2.6 for RHEL 9 s390x Red Hat Ansible Automation Platform 2.6 for RHEL 9 ppc64le Red Hat Ansible Automation Platform 2.6 for RHEL 9 aarch64 Red Hat Ansible Inside 1.4 x86_64 Red Hat Ansible Inside 1.4 s390x Red Hat Ansible Inside 1.4 ppc64le Red Hat Ansible Inside 1.4 aarch64 Red Hat Ansible Developer 1.3 for RHEL 10 x86_64 Red Hat Ansible Developer 1.3 for RHEL 10 s390x Red Hat Ansible Developer 1.3 for RHEL 10 ppc64le Red Hat Ansible Developer 1.3 for RHEL 10 aarch64 Red Hat Ansible Developer 1.3 for RHEL 9 x86_64 Red Hat Ansible Developer 1.3 for RHEL 9 s390x Red Hat Ansible Developer 1.3 for RHEL 9 ppc64le Red Hat Ansible Developer 1.3 for RHEL 9 aarch64 Fixes BZ - 2456187 - CVE-2026-39373 JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens BZ - 2484099 - CVE-2026-34993 aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() BZ - 2484377 - CVE-2026-44545 daphne: daphne: Denial of Service via excessive WebSocket message size BZ - 2486729 - CVE-2026-52902 awxkit: path traversal via YAML !include directive BZ - 2487946 - CVE-2026-44705 tmp: path Traversal via unsanitized prefix/postfix enables directory escape BZ - 2488480 - CVE-2026-12143 form-data: form-data: Form field override via CRLF injection BZ - 2500041 - CVE-2026-59886 pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values BZ - 2509975 - CVE-2026-67325 gitpython: GitPython: Command Injection via Git option prefix abbreviation BZ - 2509976 - CVE-2026-67323 gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options BZ - 2510021 - CVE-2026-67322 gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL BZ - 2510032 - CVE-2026-67324 gitpython: GitPython: Arbitrary Code Execution via Joined Short Options Bypass BZ - 2510825 - CVE-2026-69244 aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses BZ - 2510831 - CVE-2026-69243 aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade BZ - 2511095 - CVE-2026-15307 django: Django: Remote code execution via GeoDjango spatial lookups BZ - 2511900 - CVE-2026-71364 awx: project archive extraction allows path traversal file writes BZ - 2511901 - CVE-2026-71365 awx: webhook status callback SSRF leaks the Git PAT BZ - 2511902 - CVE-2026-71366 awx: notification backends allow SSRF and credential leakage BZ - 2515261 - CVE-2026-73620 gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding CVEs CVE-2026-12143 CVE-2026-15307 CVE-2026-34993 CVE-2026-39373 CVE-2026-44545 CVE-2026-44705 CVE-2026-52902 CVE-2026-59886 CVE-2026-67322 CVE-2026-67323 CVE-2026-67324 CVE-2026-67325 CVE-2026-69243 CVE-2026-69244 CVE-2026-71364 CVE-2026-71365 CVE-2026-71366 CVE-2026-73620 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Ansible Automation Platform 2.6 for RHEL 10 SRPM ansible-creator-26.8.0-1.el10ap.src.rpm SHA-256: d97cd659f6d43f2430643218bff8099cf553bfbee953860ba86e112b64052b14 ansible-dev-environment-26.8.0-1.el10ap.src.rpm SHA-256: 774f53b1c0e389ffdde3007271c6b86a529385e8fd9477af935a1018e5f5d46e ansible-dev-tools-26.8.0-1.el10ap.src.rpm SHA-256: 7ba593187fcb91e77a91feae8ea8940696e8bde7efe2e56354773ef222e1b424 ansible-lint-26.8.0-1.el10ap.src.rpm SHA-256: 6f94ceda19ede1f8d6ab210a7f1424d1324848ef022b2adce228839a460dfab1 ansible-navigator-26.8.0-1.el10ap.src.rpm SHA-256: 0d9f7ae6b76f38b89d39cf1e1f92d0c96686bc74be81b3cb38fe674ad0f7c2a0 molecule-26.8.0-1.el10ap.src.rpm SHA-256: dace332b7a12cb0b9145faaf48bcbffd434f132d327a90005d08b2757dd06d38 python-django-5.2.17-1.el10ap.src.rpm SHA-256: 9d7e4f737bee2c1a2261692ac5f6d6a5d61ccc14e669971bedd2c3adbb54eff9 python-pytest-ansible-26.8.0-1.el10ap.src.rpm SHA-256: 754b957a551233bc492127e9d5adf2b56f95b318300270abecdd2befc9800e5a python-tox-ansible-26.8.0-1.el10ap.src.rpm SHA-256: a8c3c51c7fc64793d60ef8a65169685c773f1c5489a0692ec54da2ecf0d3e2b0 x86_64 ansible-creator-26.8.0-1.el10ap.noarch.rpm SHA-256: 8e171a0ef04f48c9f82ca6814c4718ea6e42ef491d4768f4abf59b659445e676 ansible-dev-environment-26.8.0-1.el10ap.noarch.rpm SHA-256: deaba6e1ca323e6b5db69a453bdd2b6767267b25dbfbc806bf9e76ba90d8a320 ansible-dev-tools+server-26.8.0-1.el10ap.noarch.rpm SHA-256: 9d26e4c40cc352d929b11e2c103ddddf3d758ffc930f2eb3aa78a24a2740b2f3 ansible-dev-tools-26.8.0-1.el10ap.noarch.rpm SHA-256: 824f5ab755e1430a95f6850b333a44139d05209049a1aef9ebceee19bb1081c5 ansible-lint-26.8.0-1.el10ap.noarch.rpm SHA-256: 2af8d9ac5d0a8c6537bf1a9864c3bb430f453fbf599252d3692143c98242872b ansible-navigator-26.8.0-1.el10ap.noarch.rpm SHA-256: b6d80a1a0f5d5213c92a03d0a91c0f0bcc5111abf9b65f8df9169ee0c57acd04 molecule-26.8.0-1.el10ap.noarch.rpm SHA-256: 7d07255296571d002192c82680a55c44ae468c0110e9c2414b689d28a4aa9828 python3-django-5.2.17-1.el10ap.noarch.rpm SHA-256: 594353a4337dfc843bd3bd4dc5528df964ead7cb1dea6f7f83f9354612c91c20 python3-pytest-ansible-26.8.0-1.el10ap.noarch.rpm SHA-256: c67a0a5c5aa307ff4ddc4f2cc43a3f1199ed1cdf3aef8592fd7b8e4a9ae7f6f5 python3-tox-ansible-26.8.0-1.el10ap.noarch.rpm SHA-256: a41628ec716fc347d7036e2ead746cbf72778e7ad32cdad9d6e24304e2416f55 s390x ansible-creator-26.8.0-1.el10ap.noarch.rpm SHA-256: 8e171a0ef04f48c9f82ca6814c4718ea6e42ef491d4768f4abf59b659445e676 ansible-dev-environment-26.8.0-1.el10ap.noarch.rpm SHA-256: deaba6e1ca323e6b5db69a453bdd2b6767267b25dbfbc806bf9e76ba90d8a320 ansible-dev-tools+server-26.8.0-1.el10ap.noarch.rpm SHA-256: 9d26e4c40cc352d929b11e2c103ddddf3d758ffc930f2eb3aa78a24a2740b2f3 ansible-dev-tools-26.8.0-1.el10ap.noarch.rpm SHA-256: 824f5ab755e1430a95f6850b333a