RHSA-2026:42080HighCVSS 8.2
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Product Security and Bug Fix Update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-11332 — ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:42080
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.7/whats_new-async_updates
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.7#Upgrade
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484207
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485379
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42080.json