Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
🔗 CVE IDs covered (11)
📋 Description
CVE-2025-14550 — Django: Django: Denial of Service via crafted request with duplicate headers
CVE-2025-69534 — python-markdown: denial of service via malformed HTML-like sequences
CVE-2026-6266 — aap-controller: aap-gateway: Account hijacking and unauthorized access via unverified email linking
CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID
CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url
CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns
CVE-2026-27459 — pyOpenSSL: DTLS cookie callback buffer overflow
CVE-2026-27606 — rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability
CVE-2026-30922 — pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation)
CVE-2026-39373 — JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:13508
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/html/release_notes/patch_releases
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2430472
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2441268
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442530
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2444839
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2445356
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2447194
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448503
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448553
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456187
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458142
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_13508.json