Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-33154 — dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection CVE-2026-41240 — DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization CVE-2026-42035 — axios: Axios: Arbitrary HTTP header injection via prototype pollution CVE-2026-44293 — protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
🎯 Affected products62
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.13-2.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.13-2.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.13-2.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.13-2.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.13-2.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-cli-0:4.7.13-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-server-0:4.7.13-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-ui-0:4.7.13-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-venv-tower-0:4.7.13-2.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-venv-tower-0:4.7.13-2.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-venv-tower-0:4.7.13-2.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-venv-tower-0:4.7.13-2.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-0:1.2.9-3.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-0:1.2.9-3.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-base-0:1.2.9-3.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-base-services-0:1.2.9-3.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-event-stream-services-0:1.2.9-3.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-worker-services-0:1.2.9-3.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-gateway-0:2.6.20260701-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-gateway-0:2.6.20260701-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-gateway-config-0:2.6.20260701-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-gateway-server-0:2.6.20260701-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-hub-0:4.11.10-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-hub-0:4.11.10-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-platform-ui-0:2.6.10-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-platform-ui-0:2.6.10-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- python3.12-django-ansible-base+activitystream-0:2.6.20260701-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- python3.12-django-ansible-base+api_documentation-0:2.6.20260701-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- python3.12-django-ansible-base+authentication-0:2.6.20260701-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- +32 more not shown
✅ Remediation
For details on how to apply this update, refer to Ansible Automation Platform documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:34160
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2449774
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461147
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461606
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2466684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477104
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477167
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482734
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487949
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_34160.json