Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
🔗 CVE IDs covered (14)
📋 Description
CVE-2026-12383 — eda-server: ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN CVE-2026-18141 — aap-gateway: aap-gateway: Authentication bypass in Event-Driven Ansible via forged HTTP header CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-40898 — github.com/quic-go/quic-go: quic-go: Denial of Service via excessive memory allocation in HTTP/3 trailers CVE-2026-44545 — daphne: daphne: Denial of Service via excessive WebSocket message size CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVE-2026-54059 — python-pillow: Pillow: Denial of Service via crafted PCF font data CVE-2026-54060 — python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files CVE-2026-55379 — python-pillow: Pillow: Denial of Service via crafted BDF font file CVE-2026-55380 — python-pillow: Pillow: Denial of Service via crafted GD 2.x image file CVE-2026-59197 — Pillow: Pillow: Native heap out-of-bounds write CVE-2026-59885 — pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values
🎯 Affected products135
- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- aap-metrics-utility-0:0.7.6-3.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- aap-metrics-utility-0:0.7.6-3.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- aap-metrics-utility-0:0.7.6-3.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- aap-metrics-utility-0:0.7.6-3.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- aap-metrics-utility-0:0.7.6-3.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- ansible-dev-tools+server-0:26.7.2-1.el10ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 10
- ansible-dev-tools+server-0:26.7.2-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- ansible-dev-tools-0:26.7.2-1.el10ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 10
- ansible-dev-tools-0:26.7.2-1.el10ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 10
- ansible-dev-tools-0:26.7.2-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- ansible-dev-tools-0:26.7.2-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.15-2.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.15-2.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.15-2.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.15-2.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-0:4.7.15-2.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-cli-0:4.7.15-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-server-0:4.7.15-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-ui-0:4.7.15-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-venv-tower-0:4.7.15-2.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-venv-tower-0:4.7.15-2.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-venv-tower-0:4.7.15-2.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-controller-venv-tower-0:4.7.15-2.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-0:1.2.11-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-0:1.2.11-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-base-0:1.2.11-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-base-services-0:1.2.11-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- automation-eda-controller-event-stream-services-0:1.2.11-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.6 for RHEL 9
- +105 more not shown
✅ Remediation
For details on how to apply this update, refer to Ansible Automation Platform documentation. Workaround: The following practices would help for avoiding exposure and mitigate this flaw: - Ensure the EDA server is not directly accessible from untrusted networks; all traffic should route through the AAP Gateway which should perform mTLS validation. - If possible, configure network-level access controls to restrict which source IPs can reach the EDA backend API. - Monitor EDA event streams for unexpected events_received counter changes. - Review and rotate mTLS client certificates if unauthorized access is suspected, as the expected DN may have been leaked via the 403 error response. Workaround: Restrict network access to the EDA event stream endpoints at the firewall or load balancer level. Ensure that only trusted sources are permitted to reach the event stream ports. Additionally, monitor EDA event logs for any unexpected events originating from unverified sources. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Do not load PCF fonts from untrusted sources. If PCF font loading is required, validate font file dimensions before passing them to Pillow, or upgrade to Pillow 12.3.0 or later which includes the fix for this vulnerability. Workaround: Do not load BDF font files from untrusted sources. Applications that only process standard image formats (PNG, JPEG, etc.) and do not use BdfFontFile or ImageFont.load() with BDF files are not affected. Workaround: Avoid processing untrusted GD 2.x image files with PIL.GdImageFile.open(). Use Image.open() instead, which includes decompression bomb protections for supported formats. If GdImageFile must be used, validate the image dimensions before calling load(). Restricting accepted image formats at the application boundary to only those explicitly needed can reduce exposure. Workaround: Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1 input are at reduced risk. Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2026:50336
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2482734
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484099
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484377
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484875
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489127
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2497452
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2497455
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2497464
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2497466
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2500041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2500043
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2500380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2508155
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50336.json