RHSA-2026:34374HighCVSS 8.1

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update

Published
July 1, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite CVE-2026-33154 — dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-44188 — ansible-lightspeed: Ansible Lightspeed: Session hijacking and unauthorized data access due to insufficient session expiration CVE-2026-44293 — protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens

🎯 Affected products119

  • Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:51e90eeed5c6bf2e6355ee9ba50fe330149b7c2b7633a106946459e8984d82ae_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:5e9de77acecac9653b91d2ebbfc5be8dc47da81e9e3e1772d38f827f05779632_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:7cefb007f075c5b1e0265fe8b12888218201cb453e9ebac315d91a79ed6e686a_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:bd4450e5af03c053f28e9c2ca0f2a2c016fc55fef4187676bc4edd5149c1a0f4_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:21243b5bb27b62467a311f0dfb5001384b424c095e17eba2c4fa441d7a03f7cf_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:22190a2714d3942a57dbe9dd265570bfe179b8d7f3e412173d010090de2bb98d_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:35b39d818bfb7b3fe86f77eedb134d12e9f316ce1642f86a8fa5ce1c1e31f37b_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:3f2e1942032818fe9c91bf18948b80002a713b81c96e8ef5a3a4178a24899fb7_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:25928bb67eadad3a0d3b23da81acb313b8f873476250ddc6481cfb06bc25b8ab_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:bdfafa3b05bea80b81ffdc63cd77d4b2a96588ccd309aba83de0a683cb07c3c4_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:d7aa74297e76cb375c4bdd939c673739e34e22d83f8ef8846b1aa3c3c2264bbe_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:ea75fa4468a26357ce7c92614d70bc41ff0f8a8e562978a5b2bdfa5563492090_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:49025eb304ed55e363338fbe74b8dd77815b4d87183f1cb0cbfbbba71c2d2c59_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:54524172989364298f5cce342ef854f62fd59c75a42be804af3f286c6585b3d1_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:c1d135f85a4a1c5fe1c86509658d3056ce4bf748e8210274756064e18f991440_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:fb2eb12e6a6159c75e56f58429789cc0ac74af2a3d04f9ab865c8d86576e8c15_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:1252d44baa18b442de12a9659d3419ef77148e47ca14747ae684b8541fe795a7_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:4750bc9a80e819747b9d6576d21e348634f0dd4bc56190a662e22b2c80172bbd_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:5988a2daac19ccd72b8eec8cd1d9b623c69aed7be1a4223070d2c65256210776_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:eac25bae75a0e08a0aae706325faae2606ee8b0c086559cc0b89a59501a511f8_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:4c56fcde717c7a7957638fa6624a6ba5a9fc372bc9056e924158a0477410c9e7_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:5f5b5adc67e0655dcc3bcaaa4bb75337ebff130cca2e019d553be7521ca71871_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:91438ae17f6ee162df0d564fe47c8690a5246315e26fa4ebfa16dc8c93425cb7_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:df6617374f5f70f6ff53a980d38ddda8ab1aca125894eadc3a1932ba7612626d_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:49d0f2c55661dd973b0a15ba0e096c54badf4e0017093dfee373a655d47373f0_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:5bbbcaa71f5bf11922738e37c1155c5e60ebc5166a67690f5e5218a42b946366_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:99446549dca0b1cd38919ed7489e3eff72b1e4dd739e4f4e914d6c3ca6076b58_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:cf59b3a7897d59615e746c14697a289d79afbc18a9d2e7e7b5f7b1242d640b02_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/eda-controller-rhel9-operator@sha256:6e7f3aa6bb48cbe35d205d5f4c9ea251945dcdcce9b40cd49676705d778d9500_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • +89 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (17)