RHSA-2026:50357HighCVSS 7.8

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Container Release Update

Published
August 4, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-9595 — webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration CVE-2026-11332 — ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-44545 — daphne: daphne: Denial of Service via excessive WebSocket message size CVE-2026-55379 — python-pillow: Pillow: Denial of Service via crafted BDF font file CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59939 — httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodies

🎯 Affected products103

  • Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:04a3b51ccd209001d37be817db54e8be8d492962e7285d1a9aa37c3ec029127a_arm64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:a042aadc2d6ea7170de1bb0bcb1dda384cb8359df490e0e8c62e444cbd1fcdf2_s390x as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:a7f4405703bff7d5a45c8182d53e631618591656024180d64ca744e13f99f8df_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:b0fb268976bdff53726713cbcf17cf3e3b00b9e9aa85cd58760bae5012ac188c_amd64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:1137dd3357ca693226837112bc8470cb507da06cc278a1bfb9d0931888908bb6_arm64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:2bc893b56985d11c0e1da2c7c5acfb240cf5301a83f78a6b50d85306031c94d3_amd64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:397a4371bfc793cbaf02e5a10631f01f50afcfb0978513f52d6f05b116b0faf5_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:eac647745959fe43f61532a25dc5d8542048486eae4f6e3490806ba035b3228e_s390x as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:3e4745f39304fc29a565a0af8ccb21fcabe7908b01adfa3ba8462345a0ca11a8_amd64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:636e387a445b0d20ee029d4564756915ab608935778aff47d4346eecc78498bf_arm64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:800132c135f380343666e3169f74b2b937f4861451378de74ebb8f215e2e3fd8_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:d0f819175f8bcd7950ed290102177534adbc51fe068b29afd4a4a2e58ee8a335_s390x as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:242f1d3c6b75153386a6fdd6939f0058f71e6095b41f321436241ad62831fbb8_arm64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:a03b79e96eaca0ece70c07489673e1c920bb304d4dd5ff737ed913579377fc88_amd64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:b2f58d067e34cf34c848dc49b91224d020e6d04803b1fb835cccaafb02607c67_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:f00d5f3925084d6cb0fadc296c7b98af710c30d440da5d3ef6b955cafdc3f7fd_s390x as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:66e6f6bcd4510a99612245e9b4039d8069c986a14c71b4b8544d998f8e25c740_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:86dd023a27b7f1a2518b7837ee68fd6bcd5c8e4ef8135a72c8c0c3354619b940_s390x as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:8c60b69a90a5de910c48e8fdc90eec5caf9dce2ca0cf4e19d6c945dae262ecba_amd64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:c04002c198f38d8a3f98de402d39b9afa1f18599773c3b9788db058c3aaf3d3f_arm64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:7718498e7db5af059d48c7f741e5e32b78b0920fafb5944a6dc2c342b773de3c_s390x as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:a8459534738f4a24c34a35869ed1ac747b929062d431215d265faeab32625b13_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:eb4aba2fdeb45dd7bacbb1bdd7acab92183320b5c7babc2ef67980bb27f45ef1_amd64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:fd5b7470e2e6d6de5654505e08c4056bb4e31019bbdbea0504986aa79b42efdf_arm64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:9220943500bf9aaed5f6fbaeb57d20e5fd65cdf6a5cdfb444cc62cdd45b4287e_s390x as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:d14575c03dae9d86c1dee02e7a4782df3ec2c22f867c58f9ec7f12c30f198127_amd64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:dea15b152ad417d5ecd57b8cb8bbf98f41b60d5f1aeca7665672062d14c4e4e0_arm64 as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:edb144f7fc61077b0ecadcc40c30e710c590e7dd8d3be4a8841c999b02e36a10_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
  • registry.redhat.io/ansible-automation-platform-25/de-minimal-rhel8@sha256:3168867fb72b22e494194947c09e73d913f7b35241cb179f7d8f9fb70c63bdde_s390x as a component of Red Hat Ansible Automation Platform 2.5
  • +73 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading Workaround: To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: Do not load BDF font files from untrusted sources. Applications that only process standard image formats (PNG, JPEG, etc.) and do not use BdfFontFile or ImageFont.load() with BDF files are not affected. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (12)