Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
🔗 CVE IDs covered (16)
📋 Description
CVE-2026-15307 — django: Django: Remote code execution via GeoDjango spatial lookups CVE-2026-34993 — aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() CVE-2026-39373 — JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-52902 — awxkit: path traversal via YAML !include directive CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values CVE-2026-67322 — gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL CVE-2026-67323 — gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options CVE-2026-67324 — gitpython: GitPython: Arbitrary Code Execution via Joined Short Options Bypass CVE-2026-67325 — gitpython: GitPython: Command Injection via Git option prefix abbreviation CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses CVE-2026-71364 — awx: project archive extraction allows path traversal file writes CVE-2026-71365 — awx: webhook status callback SSRF leaks the Git PAT CVE-2026-71366 — awx: notification backends allow SSRF and credential leakage CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding
🎯 Affected products88
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-0:4.6.32-1.el8ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-0:4.6.32-1.el8ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-0:4.6.32-1.el8ap.s390x as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-0:4.6.32-1.el8ap.src as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-0:4.6.32-1.el8ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-0:4.6.32-1.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-0:4.6.32-1.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-0:4.6.32-1.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-0:4.6.32-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-0:4.6.32-1.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-cli-0:4.6.32-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-cli-0:4.6.32-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-server-0:4.6.32-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-server-0:4.6.32-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-ui-0:4.6.32-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-ui-0:4.6.32-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-venv-tower-0:4.6.32-1.el8ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-venv-tower-0:4.6.32-1.el8ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-venv-tower-0:4.6.32-1.el8ap.s390x as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-venv-tower-0:4.6.32-1.el8ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-controller-venv-tower-0:4.6.32-1.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-venv-tower-0:4.6.32-1.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-venv-tower-0:4.6.32-1.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-controller-venv-tower-0:4.6.32-1.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-eda-controller-0:1.1.22-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-eda-controller-0:1.1.22-1.el8ap.src as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
- automation-eda-controller-0:1.1.22-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- automation-eda-controller-0:1.1.22-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 9
- +58 more not shown
✅ Remediation
For details on how to apply this update, refer to Ansible Automation Platform documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications using AIOHTTP that are configured to load untrusted files via the `CookieJar.load()` function should implement input sanitization prior to loading. This prevents the injection of malicious code. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: The following practices would help for avoiding exposure to this flaw: 1) Prioritize the default JSON import format instead of YAML. 2) Avoid importing YAML files from untrusted sources. Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion. Workaround: To mitigate this issue, ensure that applications using GitPython's Repo.clone_from() method to clone from untrusted sources operate within a process environment that does not contain sensitive information as environment variables. Alternatively, implement strict validation and sanitization of all Git repository URLs before they are passed to Repo.clone_from() to prevent the inclusion of environment variable tokens. If the application is a service, a restart may be required for environment variable changes to take effect. Workaround: To mitigate the risk, ensure that applications utilizing GitPython are run within a sandboxed environment with minimal privileges. This limits the potential impact of arbitrary command execution or file truncation if an attacker successfully exploits the vulnerability through an application processing untrusted input. Review applications that interact with GitPython to ensure all input is properly sanitized and validated before being passed to methods such as Repo.archive(), git.ls_remote(), Repo.iter_commits(), or Repo.blame(). Workaround: There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Avoid using archive-type projects (scm_type='archive') until the fix is applied. Use Git-based projects (scm_type='git') instead where possible, as these do not use the vulnerable extraction code path. 2. Ensure all archive source URLs use HTTPS with valid certificates to prevent man-in-the-middle attacks on archive downloads. 3. Only configure archive-type projects with sources from trusted, verified providers. 4. Restrict the ability to create and modify projects to trusted administrators. 5. In containerized deployments, review execution environment container configurations to minimize host volume mounts and ensure the extraction runs with minimal filesystem permissions. Workaround: There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Restrict the admin role on webhook-enabled job templates to trusted personnel who already have legitimate access to the associated Git credentials. 2. Use Git credentials with the minimum required scope (e.g., read-only access to the specific repository) to limit the impact of credential leakage. 3. Implement network egress filtering on the Automation Controller nodes to prevent outbound connections to non-allowlisted hosts. Block outbound connections to loopback (127.0.0.0/8), private (RFC1918), and link-local (169.254.0.0/16) address ranges. 4. Monitor for unusual outbound connections from the Controller node to unexpected destinations. 5. Rotate Git PAT credentials periodically and after any suspected compromise. Workaround: There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Restrict the ability to create and modify notification templates to trusted administrators who have legitimate need for this capability. 2. Implement network egress filtering on the Automation Controller nodes to block outbound connections to loopback (127.0.0.0/8), private (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and link-local (169.254.0.0/16) address ranges. 3. Monitor notification template configurations for URLs pointing to internal or unusual addresses. 4. Avoid configuring sensitive credentials (Basic Auth, Grafana API keys) in notification templates until the fix is applied. Use notification backends that do not require credentials where possible. 5. Review and audit existing notification templates for URLs pointing to internal services.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2026:59135
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456187
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484099
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486729
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487946
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2500041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2509975
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2509976
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510021
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510032
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510825
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510831
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511095
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511900
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2511902
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2515261
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59135.json