Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update
🔗 CVE IDs covered (17)
📋 Description
CVE-2025-4565 — python-protobuf: Unbounded recursion in Python Protobuf CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-53643 — aiohttp: AIOHTTP HTTP Request/Response Smuggling CVE-2025-59057 — react-router: @remix-run/router: React Router XSS Vulnerability CVE-2025-61140 — jsonpath: jsonpath: Prototype Pollution vulnerability in the value function CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2025-69223 — aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb CVE-2026-1207 — Django: Django: SQL Injection via RasterField band index parameter CVE-2026-1287 — Django: Django: SQL Injection via crafted column aliases CVE-2026-1312 — Django: Django: SQL injection via crafted column aliases in QuerySet.order_by() CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) CVE-2026-21884 — react-router: @remix-run/react: React Router SSR XSS in ScrollRestoration CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking CVE-2026-24486 — python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability CVE-2026-25536 — @modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak
🎯 Affected products107
- Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:04782521f67f3a0b872f9c1f31abde6ea21e96716795b1403b1291420b7660b1_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:83cd0bb050432784fcace087cb7aff023b8b27eb043484485b2a4bb5000dab10_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:a77144a3d2526cc8414d5171194a9646043543bf8e957ed85aae53b2081145e8_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:c127c310cd19cab8a6508ec6809282e7b39c9c13dd6c3ff02ebf2290f0d08209_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:880ca66b04111d9591e7dee88b2ed7ba0813b779e8afb89e6d8bddae712e4561_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:88bea929117192f7d91530d07514329cfc308d4c18650519a467b3e153e2c8fa_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:e4c7e1bbe0733f7ea6405988c830dbceda1874a0fd75347180176f75ca620bde_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:fbb8ca3a9880131f22df9635e3ce47099bcd22746bc8b4e15a2911f08fe7f0be_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:8e62d5cad01933db06ad7d3ab48ef264555703f9fdbf5be5d61889abdafdbb6a_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:a2e1a2f25a111dc6e561f8ca7e9f36e757fb209fa5077ad400a0232a9d77a6b9_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:bebb7ba186ff9fe05642c43fa746ee9d5f45cd113f6f02795ef37646e5010cdc_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:e219423babd602aaab802270a32325d360579869fc02d6b1cedb34dfe8208c63_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:0278a84ee576d50ff71f1bf9f94359db5a37d0e287679ed1416a4dbe195ed0c9_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:7ce518de425de424d1c812ed551fa8d33eca6a0c3035e1462b3b55340228627a_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:95f1967f81c4087ebc318754761af3a3f3add716eaebd8c4c073a9b7d7184413_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:d0ed37b0b3278e2c302c2853916a1642b0c4d5d683a18f9fc1733941636603b7_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:3e900373f5583d10d89a9df8b3b9bcda13e5fa026207d7653e1adcb6fa6137a3_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:ae8d0532b14b302ec8eac7c780408a600265a1753d24d9b8803576c96bf8dcdc_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:e52468f315f13aea0d1f731f9c6d3bf0e5f2b2d766fc3d6acc74a28244626569_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:fa72e463380551bb7fb7373c1c3ffbcc9915f958a2e8d7ae730e7b42a5708ecd_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:0aa644f1468c480b6879e4d58b81e20138e0b3955b6e9d916f920a4c7971018c_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:7b01dfa70aa64c598318647c123686be7af408f445987e04935b306b757a91e5_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:7d8b5f957dc46d6b0070e4a0a21d74f697f43b732a3c1ea076ea658f07b79eba_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:d4e558b5ed8016da41d717e0093af818fbd4d963bc6fb49d9aa351616c7cfb3b_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:3a956b6f88ab196287e34cc0a819b4090b29192e3c08db85a936ac85a2ef5890_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:93aaf4b5788954f8022d53884be030b5ea2d029e15e5b1657e73bbe35df243f6_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:c143e1af98ff9a4868ddac09d133b103c3e666828f559b238f1b78fd041edae9_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:e951ba4e617e17e8252a1546412ffc08517dc89cb741a7aae94835b51f795f01_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/eda-controller-rhel9-operator@sha256:20d10d442ff860ccc9ea105009a967ac15b001c88842b7f605cd4a18a130ff59_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- +77 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, avoid enabling the `UPLOAD_KEEP_FILENAME=True` configuration option in applications using `python-multipart`. This option, when used with `UPLOAD_DIR`, allows an attacker to write files to arbitrary locations. Disabling or not configuring `UPLOAD_KEEP_FILENAME=True` prevents the path traversal vulnerability.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2026:3960
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-4565
- externalhttps://access.redhat.com/security/cve/CVE-2025-53643
- externalhttps://access.redhat.com/security/cve/CVE-2025-59057
- externalhttps://access.redhat.com/security/cve/CVE-2025-61140
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-66471
- externalhttps://access.redhat.com/security/cve/CVE-2025-69223
- externalhttps://access.redhat.com/security/cve/CVE-2026-1207
- externalhttps://access.redhat.com/security/cve/CVE-2026-1287
- externalhttps://access.redhat.com/security/cve/CVE-2026-1312
- externalhttps://access.redhat.com/security/cve/CVE-2026-21441
- externalhttps://access.redhat.com/security/cve/CVE-2026-21884
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-24049
- externalhttps://access.redhat.com/security/cve/CVE-2026-24486
- externalhttps://access.redhat.com/security/cve/CVE-2026-25536
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/html/release_notes/patch_releases#aap-26-20260225
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3960.json