RHSA-2026:59153HighCVSS 8.8

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update

Published
August 24, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (15)

📋 Description

CVE-2026-9595 — webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-15307 — django: Django: Remote code execution via GeoDjango spatial lookups CVE-2026-27459 — pyOpenSSL: DTLS cookie callback buffer overflow CVE-2026-39363 — Vite: Vite: Information disclosure via WebSocket connection bypasses access control CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration CVE-2026-44545 — daphne: daphne: Denial of Service via excessive WebSocket message size CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-46625 — js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses CVE-2026-71364 — awx: project archive extraction allows path traversal file writes CVE-2026-71365 — awx: webhook status callback SSRF leaks the Git PAT CVE-2026-71366 — awx: notification backends allow SSRF and credential leakage

🎯 Affected products63

  • Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/aap-must-gather-rhel9@sha256:38767bc5b845584e40af76a5527511498d96cc176e12ecbe5fee2cde298d34b1_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/aap-must-gather-rhel9@sha256:65bbd3871114b352e90c1b5bb23aa374863929b3f5627fe91afa75a416ddc481_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-builder-rhel9@sha256:8ab212a01e697bb1763e09a44919a84608c27371f93b5d83998d8487669acfc3_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-builder-rhel9@sha256:e56f274e22a999a76f60221325a5e0f73e19b25c70f8be9871cdd6fcd9bc243a_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-dev-tools-rhel9@sha256:42a618508551b70926f35610eef57980659ae4badb422052f8301e717d5b2983_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-dev-tools-rhel9@sha256:b2993aef8fe8a52397b7f693bd8f927398c3709488aa3e1210d3785eea399d59_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-devspaces-rhel9@sha256:379afbda6da87360c8a75438650d4f8f40224519bd9e6067e815fac42a46450b_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-devspaces-rhel9@sha256:7b8e1f8b34ad5641e130e24b7c3809c53f61de3b36e94c4ea81489f1852cbf3a_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9-operator@sha256:074034bce39fd2b838ac9900b124d70d75e480eb7272fbb4fff33a2a037b9384_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9-operator@sha256:2be8afe3ea1e9084d3524225e990d10a39f3e7cacd10a5693da546f0171cf77d_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9@sha256:1671d67b8e2b4d3b4ceb6c5b2bf5e008c7eacf6390745113b85709bc303aed4b_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9@sha256:e94b1dd9ac4dbad9658318b86eabb37b1433a65a3ef829c35411552ccdf98f09_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-minimal-rhel9@sha256:7085fdb29cd8ca97c088ab6ef18d553cfeaf4131ed49e01383e8c8c2814caaa1_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-minimal-rhel9@sha256:9d04f0a9793b0fbc1874b5399d475fa9bbad9dd166eac24ec54bd74c63837b09_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-supported-rhel9@sha256:26488b8ab2699e84be3e430853b25de889e5abd1bc8ae457786852afb4507899_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-supported-rhel9@sha256:c12da193d389ff5997744cb7e3065e2c7412ba2b171d0b2c5587dcaa1680411a_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9-operator@sha256:942dd4e41407c428c6bcea870a3b1f1d6d8f436d1e23fbf829246c5f517ca21e_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9-operator@sha256:bac7c2ec0974c64ae45ebfde34fd08dbd1c32368d6dd2b8850734949413339a1_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9@sha256:064ffb1056ba4904a013a74f9a3f562a5d98cdd0430a23b969b2315f95b8f0f1_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9@sha256:e05b56838f346ef1e4f8daca37e603f9bb7a912d19fc9c167a1f3fedf862ccc7_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-ui-rhel9@sha256:5df32fab11b9190a64e52cdce3ecf2a893c4f7eba72798112cd804cbf6e25ccd_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-ui-rhel9@sha256:991f94d6b73b1b962074c93a8a75fe967723d721b6dce73bcb89a37664fa3ebb_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:1e9d9dd18a876a7f5ca7099f186deebb4320bc082d8ac1b1d0e72cbafae80a72_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:6217cc795a40239fa048e902dae52844c7aa4c121b59f6c6c519d4f66dadb98e_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:759d5dd6b8ff6c701982915218a24bf9c0cb3b9eb4df6b6f822a48b5db057525_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:f45c0f53123e8fcc25bd90c4f8eecc4eaa90091cb632ab39ed964141c2fa081b_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-supported-rhel9@sha256:1a112dd793f3096cb1a2b521d7e4b9d71be7410324f61894a7cf6cf8ce4b1b59_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-supported-rhel9@sha256:6a60cc17e0994428b9db4b0431d0f3d01b7fee36289d107f7fda6a73db256e5c_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/gateway-proxy-rhel9@sha256:cdddbe67aec1c8147dbc2f3aae4b8d2604f970edf368facaeb77c520bfa56b47_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • +33 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.7#Upgrade Workaround: To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this flaw, ensure the callback provided to the set_cookie_generate_callback function strictly limits the returned cookie string or byte sequence to under 256 bytes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion. Workaround: There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Avoid using archive-type projects (scm_type='archive') until the fix is applied. Use Git-based projects (scm_type='git') instead where possible, as these do not use the vulnerable extraction code path. 2. Ensure all archive source URLs use HTTPS with valid certificates to prevent man-in-the-middle attacks on archive downloads. 3. Only configure archive-type projects with sources from trusted, verified providers. 4. Restrict the ability to create and modify projects to trusted administrators. 5. In containerized deployments, review execution environment container configurations to minimize host volume mounts and ensure the extraction runs with minimal filesystem permissions. Workaround: There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Restrict the admin role on webhook-enabled job templates to trusted personnel who already have legitimate access to the associated Git credentials. 2. Use Git credentials with the minimum required scope (e.g., read-only access to the specific repository) to limit the impact of credential leakage. 3. Implement network egress filtering on the Automation Controller nodes to prevent outbound connections to non-allowlisted hosts. Block outbound connections to loopback (127.0.0.0/8), private (RFC1918), and link-local (169.254.0.0/16) address ranges. 4. Monitor for unusual outbound connections from the Controller node to unexpected destinations. 5. Rotate Git PAT credentials periodically and after any suspected compromise. Workaround: There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Restrict the ability to create and modify notification templates to trusted administrators who have legitimate need for this capability. 2. Implement network egress filtering on the Automation Controller nodes to block outbound connections to loopback (127.0.0.0/8), private (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and link-local (169.254.0.0/16) address ranges. 3. Monitor notification template configurations for URLs pointing to internal or unusual addresses. 4. Avoid configuring sensitive credentials (Basic Auth, Grafana API keys) in notification templates until the fix is applied. Use notification backends that do not require credentials where possible. 5. Review and audit existing notification templates for URLs pointing to internal services.

🔗 References (19)