RHSA-2026:42132HighCVSS 9.1

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update

Published
July 20, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (16)

📋 Description

CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite CVE-2026-12701 — pulpcore: pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39373 — JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options CVE-2026-42561 — python-multipart: python-multipart: Denial of Service via excessive multipart part headers CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVE-2026-48746 — vllm: starlette: vLLM: Critical authentication bypass allows unauthorized API access CVE-2026-54283 — starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS

🎯 Affected products119

  • Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:140406a92b8fb788f8f8d785605d9ca3f2f6d0a7a35995d9a76ca6a8eec69440_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:1e6917b6817106c5e0faff0e774c36e20499a3742852344fa27fbce111d8f501_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:87e1132296ee470e75f2a6b397e655620a574e857d3f406c1f4aa9741054194b_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:f2d3b4667c1b2069db925ca15ca71d35bf803be928300ab9f80c60f7d56a442d_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:40f291935f6e1f189494b984a3d29406f19cb593caae003a0c3e1d0e002c250a_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:5f521f05bf2675028d51f88f71278e6aae1ee139d3680054aa66168a5a1334bd_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:d5fcb7cd5b0d83c090104f0aac3ac7c28d9c4d43781639fd2c2b1ab943559b12_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:eb36bf4b06202551e8c69b869098fc97e8b1a1a2b9c495fb68a0bfee80762524_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:71b494a3a2d0b47c1fa366dcee8d17c6ee58e94e96391f36962a8c5f24a80b67_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:a1a4eae19c9e804657bb0e75c5b2d5310099423dbfca71dd8098e81b880295d5_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:a81be65e9576c554eb4db28e7368fa44769a8299f0e97f4c0f4b97d0318aba3d_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:f907a0b840518be0ebd63cf70179664fdca18fe267e2911b7c8e19170c8f1757_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:4bfdca47a1a58b0c00ae293c97ed308e1dc5b1abb2895dbd0735ba0c8b5b7ee0_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:882ed61f6219b62c27ed0c0e242ef36060e4fff9e55a704cfdcbd4801ac81a3c_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:c794a869e90be74e013941e3b21e0f422fcb06dadcc83c8fbf8b1bdb35b60ecf_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:ea876220523e7e9be975af10f07d08841e2306424fc672b6a20484e8d85e997d_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:23dcbf5698c2458253514c527581912da716b877dd519e995b476690c17bfbf5_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:5532b84e2e476a1ac64c37d3fd66336c4e08ceeb6bbf5642688fbd9969b5832e_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:e522ee8e741bd6e0c13147275b060c723a19df6ae274e764feda862019031a96_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:f07ccdc052f402000fe0e68c17e0761b5b8c694c68eba0922f40ac75ce504ba2_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:2442755274eea488b0c5231a4607303c662f3f8bff7d9f700c0d3786deb542ea_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:4e0cb7b53e6c2ab16f7008593b95856249fa839142ea9f087b0439d798d802df_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:cdae08d834a1bcbda0acf2fc20910653dfd61c6df5d74a1ea3edf9b1c17b2337_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:d28d8c9ae2efbfad7106216650ea06ae58fcebac153f22f8ebe1f70b8d44670f_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:2407d4b460d931ebcb30875b577ff64911070fa86d456af27d62cacb7a8d1761_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:8281d015375d194b0260f29664ece60fd4a65ec476c8c484472f5a7bcd459fbb_amd64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:c9026362371c56804f791d80551a3ad0f17e76db8ae45681712facb932e4e196_s390x as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:e431fdb3ae02fe17085511e27c2c882b29af00dba46d41e0afec5006e29107e1_arm64 as a component of Red Hat Ansible Automation Platform 2.6
  • registry.redhat.io/ansible-automation-platform-26/eda-controller-rhel9-operator@sha256:5694b4704797ff67d094e9a74f1ffaa83b172c75fffc36b56de23dca00edf8d0_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
  • +89 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Workaround: To mitigate this issue, users should avoid installing Python wheels from untrusted sources. It is strongly advised against using `pip install` with elevated privileges, such as `sudo`, when installing wheels. Additionally, administrators should inspect `entry_points.txt` within wheels for path separators or absolute paths before installation. Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If FilesystemExport was never configured on your deployment, you are not affected by this issue. 2. If FilesystemExporters exist in the database, audit them for path traversal sequences ("../"). Existing malicious entries must be cleaned up manually, as the validation functions documented to raise ValidationError do not actually do so in all code paths. 3. Restrict admin-level access to the Pulp API to only trusted operators. Review and audit which accounts have administrator privileges. 4. Ensure SELinux is in enforcing mode on Satellite/Pulp servers to limit the directories the Pulp service user can write to. 5. Monitor filesystem changes outside of expected Pulp directories for signs of exploitation. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: Restrict network access to the vLLM API endpoint to only trusted clients and internal networks. Implement firewall rules or network policies to limit inbound connections to the vLLM service, thereby reducing the attack surface. This operational control helps prevent unauthorized external access to the vulnerable API. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (20)