RHSA-2026:13508HighCVSS 9.1

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update

Published
May 4, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2025-14550 — Django: Django: Denial of Service via crafted request with duplicate headers CVE-2025-69534 — python-markdown: denial of service via malformed HTML-like sequences CVE-2026-6266 — aap-controller: aap-gateway: Account hijacking and unauthorized access via unverified email linking CVE-2026-12382 — aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-27459 — pyOpenSSL: DTLS cookie callback buffer overflow CVE-2026-27606 — rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability CVE-2026-30922 — pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation) CVE-2026-39373 — JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens

🎯 Affected products197

  • Red Hat Ansible Automation Platform 2.6 for RHEL 10
  • Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • ansible-core-1:2.16.18-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • ansible-core-1:2.16.18-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • ansible-core-2:2.16.18-2.el10ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 10
  • ansible-core-2:2.16.18-2.el10ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 10
  • ansible-lint-0:26.1.1-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • ansible-lint-0:26.1.1-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • ansible-lint-0:26.1.1-2.el10ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 10
  • ansible-lint-0:26.1.1-2.el10ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 10
  • ansible-test-1:2.16.18-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.11-2.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.11-2.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.11-2.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.11-2.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-0:4.7.11-2.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-cli-0:4.7.11-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-server-0:4.7.11-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-ui-0:4.7.11-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-venv-tower-0:4.7.11-2.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-venv-tower-0:4.7.11-2.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-venv-tower-0:4.7.11-2.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-controller-venv-tower-0:4.7.11-2.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-0:1.2.8-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-0:1.2.8-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-base-0:1.2.8-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-base-services-0:1.2.8-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-event-stream-services-0:1.2.8-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-eda-controller-worker-services-0:1.2.8-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • automation-gateway-0:2.6.20260422-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
  • +167 more not shown

✅ Remediation

For details on how to apply this update, refer to Ansible Automation Platform documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, wrap your markdown parsing function in a try/except block. This catches the unhandled exception, preventing both the application crash and the stack trace leak. Workaround: The following practices would help for avoiding exposure and mitigate this flaw: - Restrict network access to the non-mTLS EDA event stream route (/eda-event-streams/) at the firewall or load balancer level, allowing only trusted internal sources. - If mTLS-protected event streams are in use, ensure that only the /mtls/eda-event-streams/ route is accessible from untrusted networks. - Monitor EDA event stream activity for unexpected events_received counter increases that may indicate unauthorized event injection. - Review Envoy proxy logs for requests to the non-mTLS event stream route from unexpected source IPs. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this flaw, ensure the callback provided to the set_cookie_generate_callback function strictly limits the returned cookie string or byte sequence to under 256 bytes. Workaround: To mitigate the risk of arbitrary file writes and remote code execution, ensure that build processes utilizing the Rollup module bundler are executed within a strictly controlled and isolated environment, such as a container with minimal privileges. Restrict the file system permissions of the user or service account running Rollup to only the directories absolutely necessary for its operation. Additionally, rigorously validate all inputs, including CLI arguments, manual chunk aliases, and third-party plugins, to prevent the introduction of malicious path traversal sequences.

🔗 References (16)