Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:59135: Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update

  • What: Security and bug fix update for Red Hat Ansible Automation Platform 2.5
  • Impact: Enterprise IT automation systems affected
Read Full Article →

Red Hat Product Errata RHSA-2026:59135 - Security Advisory Issued: 2026-08-24 Updated: 2026-08-24 RHSA-2026:59135 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 2.5 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): automation-controller: notification backends allow SSRF and credential leakage (CVE-2026-71366) automation-controller: webhook status callback SSRF leaks the Git PAT (CVE-2026-71365) automation-controller: project archive extraction allows path traversal file writes (CVE-2026-71364) automation-controller: AIO HTTP: Denial of Service via malformed HTTP responses (CVE-2026-69244) automation-controller: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886) automation-controller: AIO HTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993) automation-controller: path traversal via YAML !include directive (CVE-2026-52902) automation-controller: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373) automation-gateway: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705) python3.12-aio http: HTTP Request Smuggling via WebSocket Upgrade (CVE-2026-69243) python3.12-aio http: Denial of Service via malformed HTTP responses (CVE-2026-69244) python3.12-django: Remote code execution via GeoDjango spatial lookups (CVE-2026-15307) python3.12-gitpython: Command Injection via Git option prefix abbreviation (CVE-2026-67325) python3.12-gitpython: Arbitrary Code Execution via Joined Short Options Bypass (CVE-2026-67324) python3.12-gitpython: Arbitrary code execution via command injection due to unguarded Git options (CVE-2026-67323) python3.12-gitpython: Environment variable exfiltration via attacker-controlled clone URL (CVE-2026-67322) python3.12-gitpython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section. Solution For details on how to apply this update, refer to Ansible Automation Platform documentation. Affected Products Red Hat Ansible Automation Platform 2.5 for RHEL 9 x86_64 Red Hat Ansible Automation Platform 2.5 for RHEL 9 s390x Red Hat Ansible Automation Platform 2.5 for RHEL 9 ppc64le Red Hat Ansible Automation Platform 2.5 for RHEL 9 aarch64 Red Hat Ansible Automation Platform 2.5 for RHEL 8 x86_64 Red Hat Ansible Automation Platform 2.5 for RHEL 8 s390x Red Hat Ansible Automation Platform 2.5 for RHEL 8 ppc64le Red Hat Ansible Automation Platform 2.5 for RHEL 8 aarch64 Red Hat Ansible Developer 1.2 for RHEL 9 x86_64 Red Hat Ansible Developer 1.2 for RHEL 9 s390x Red Hat Ansible Developer 1.2 for RHEL 9 ppc64le Red Hat Ansible Developer 1.2 for RHEL 9 aarch64 Red Hat Ansible Developer 1.2 for RHEL 8 x86_64 Red Hat Ansible Developer 1.2 for RHEL 8 s390x Red Hat Ansible Developer 1.2 for RHEL 8 ppc64le Red Hat Ansible Developer 1.2 for RHEL 8 aarch64 Fixes BZ - 2456187 - CVE-2026-39373 JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens BZ - 2484099 - CVE-2026-34993 aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() BZ - 2486729 - CVE-2026-52902 awxkit: path traversal via YAML !include directive BZ - 2487946 - CVE-2026-44705 tmp: path Traversal via unsanitized prefix/postfix enables directory escape BZ - 2500041 - CVE-2026-59886 pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values BZ - 2509975 - CVE-2026-67325 gitpython: GitPython: Command Injection via Git option prefix abbreviation BZ - 2509976 - CVE-2026-67323 gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options BZ - 2510021 - CVE-2026-67322 gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL BZ - 2510032 - CVE-2026-67324 gitpython: GitPython: Arbitrary Code Execution via Joined Short Options Bypass BZ - 2510825 - CVE-2026-69244 aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses BZ - 2510831 - CVE-2026-69243 aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade BZ - 2511095 - CVE-2026-15307 django: Django: Remote code execution via GeoDjango spatial lookups BZ - 2511900 - CVE-2026-71364 awx: project archive extraction allows path traversal file writes BZ - 2511901 - CVE-2026-71365 awx: webhook status callback SSRF leaks the Git PAT BZ - 2511902 - CVE-2026-71366 awx: notification backends allow SSRF and credential leakage BZ - 2515261 - CVE-2026-73620 gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding CVEs CVE-2026-15307 CVE-2026-34993 CVE-2026-39373 CVE-2026-44705 CVE-2026-52902 CVE-2026-59886 CVE-2026-67322 CVE-2026-67323 CVE-2026-67324 CVE-2026-67325 CVE-2026-69243 CVE-2026-69244 CVE-2026-71364 CVE-2026-71365 CVE-2026-71366 CVE-2026-73620 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Ansible Automation Platform 2.5 for RHEL 9 SRPM automation-controller-4.6.32-1.el9ap.src.rpm SHA-256: dd334b84d7a69a97402ea48db69b6be23c56d4fc68826e8b0f7f78218fa86a56 automation-eda-controller-1.1.22-1.el9ap.src.rpm SHA-256: 887184dee257f4ddfcc162bd48d3c4153763d1ae75c7c8348c704f07664a19cb automation-gateway-2.5.20260824-1.el9ap.src.rpm SHA-256: bfd0d9da317b49fa92613e4521a93df5f578e04e238ac5737989b866fad61ae0 automation-hub-4.10.18-1.el9ap.src.rpm SHA-256: 36cbc67e8f641cebc125839c1b1b94629bfa71a4a54d87e6db2b79c8f515bdcc python3.12-aiohttp-3.14.3-1.el9ap.src.rpm SHA-256: 087cedb828b630b14c8d4980a7c8ec232e7c31a2800060f6c705e3901e393f8e python3.12-django-5.2.17-1.el9ap.src.rpm SHA-256: 748471d704c419d68c169e32aef5f52a3c39647176fd1d15ce5af87ab85b6544 python3.12-galaxy-ng-4.10.18-1.el9ap.src.rpm SHA-256: fb0823618addae2cf197b81b48a7b0fe1004ca3d755148a8afba1a1a1f8bb914 python3.12-gitpython-3.1.59-1.el9ap.src.rpm SHA-256: df0db280289e01bf1ad87fe2d0a543085dfa3032cee34919dc43c3f938e2b579 x86_64 automation-controller-4.6.32-1.el9ap.x86_64.rpm SHA-256: ff83ecda9e239774605990174a488e277a35f90cba128efe58ffec9d540dbedf automation-controller-cli-4.6.32-1.el9ap.noarch.rpm SHA-256: c489278d26f59983aac8976811f2492b34b1c055f34fdd897be283bb43272c6e automation-controller-server-4.6.32-1.el9ap.noarch.rpm SHA-256: 4a36bd206350649193774d32c8ccbb847aa69bd2c9f5d9a1e97d2debac00c740 automation-controller-ui-4.6.32-1.el9ap.noarch.rpm SHA-256: 14f3a3a2e1eab3b02442c870e596972a612cdbc5c97568edeed9d62478e29129 automation-controller-venv-tower-4.6.32-1.el9ap.x86_64.rpm SHA-256: eeacc782e41083eda7d1cf846980170e0dbaf7f60abcd9b92aab99ac1efd6963 automation-eda-controller-1.1.22-1.el9ap.noarch.rpm SHA-256: 2a8dbd145cdef70f8d7c230a809896df0fe1285e36565be54fef3ee24edd3613 automation-eda-controller-base-1.1.22-1.el9ap.noarch.rpm SHA-256: 93e21ef44f643701678f2c3a766f80b4c9733c76f2f3a403ae65be551ad7f6c6 automation-eda-controller-base-services-1.1.22-1.el9ap.noarch.rpm SHA-256: 98bf513db31413bbfec1227025f459695fa1d5d9a7a27a6f4e01f4dea55e42ef automation-eda-controller-event-stream-services-1.1.22-1.el9ap.noarch.rpm SHA-256: 2a93d3b463d5d565d060b15e06110f6969a8358d4f42b9e3772c563315be0d0e automation-eda-controller-worker-services-1.1.22-1.el9ap.noarch.rpm SHA-256: 7e016493093c78aeaf1fac4a21d5e249614c536d6eafd359deed255453198499 automation-gateway-2.5.20260824-1.el9ap.noarch.rpm SHA-256: 0198261898d9a6f3d8f96ec5469ffbb865e0cefb20f98b719593265b04b7130f automation-gateway-config-2.5.20260824-1.el9ap.noarch.rpm SHA-256: 2f9cbbb8ad8c5dca24c0641a13da4b21ef01df6ec03e7f83afb2ac537012d6d9 automation-gateway-server-2.5.20260824-1.el9ap.noarch.rpm SHA-256: 465d3a00eeb6056d10a07d598fe0cb6e27196094a476bf937f0ef12c666f97f0 automation-hub-4.10.18-1.el9ap.noarch.rpm SHA-256: 4b319075201c1ce82300b904376220ba4996b7a6f7f71d253e58ae3af43d158a python3.12-aiohttp-3.14.3-1.el9ap.x86_64.rpm SHA-256: efdb4df7b43918749daa2fd81f3b124e13733447fe4f446ad4bac899558ab164 python3.12-aiohttp-debuginfo-3.14.3-1.el9ap.x86_64.rpm SHA-256: a80ca4471ab72aae2d2d945f90b39071ba33650ab1115e7ba0950880fbdd17b9 python3.12-aiohttp-debugsource-3.14.3-1.el9ap.x86_64.rpm SHA-256: c01953e5da4f2feabe52e3f4f1b43d39b8534c60f31e39dda00b65e9dbfa4aa5 python3.12-django-5.2.17-1.el9ap.noarch.rpm SHA-256: 0d0011410f08ee5ef5993ffc1d11d89db5b9d7a1dc268cec6c4c521bf5fb7ff7 python3.12-galaxy-ng-4.10.18-1.el9ap.noarch.rpm SHA-256: dd206a7369c9e0945251004c89afb9073bd8e43b98a3258d63b344d2477856ab python3.12-gitpython-3.1

Share this article