RHSA-2026:42144HighCVSS 8.0
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Container Release Update
🔗 CVE IDs covered (5)
📋 Description
CVE-2025-57847 — ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:42144
- externalhttps://access.redhat.com/security/cve/CVE-2025-57847
- externalhttps://access.redhat.com/security/cve/CVE-2026-44431
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-8643
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42144.json