Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update
🔗 CVE IDs covered (19)
📋 Description
CVE-2025-62718 — axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization CVE-2025-69223 — aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb CVE-2025-69227 — aiohttp: aiohttp: Denial of Service via specially crafted POST request CVE-2025-69228 — aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request CVE-2026-1615 — jsonpath: jsonpath: Arbitrary Code Execution via unsafe JSON Path expression evaluation CVE-2026-9595 — webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-15307 — django: Django: Remote code execution via GeoDjango spatial lookups CVE-2026-44545 — daphne: daphne: Denial of Service via excessive WebSocket message size CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values CVE-2026-67325 — gitpython: GitPython: Command Injection via Git option prefix abbreviation CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses CVE-2026-71364 — awx: project archive extraction allows path traversal file writes CVE-2026-71365 — awx: webhook status callback SSRF leaks the Git PAT CVE-2026-71366 — awx: notification backends allow SSRF and credential leakage
🎯 Affected products119
- Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:28f0099d727c77f0547b6df2f2e499eac0461d09f180724e128b2070dd8eb392_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:2fee1b8b2d7554925fd73e547416a7ca5301bb46791a2f382264b22f92b531a7_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:9bda2910b06e2aba65b9d8e63ad693fbae4d4abd3ffbd49e44b43a6a3eb46ae8_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:c4fad647c84d17fb4bb5b356e8a2fb865323eefcf7baf67b57438e342884e085_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:09ec7f6d84bad515ab4383267ffb144133f634cacac88e24a828ecb631f107ae_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:928f81d14f8b7cffe4770e043ca36c775f4f19444dd6ebcdeb5f94d4db172fc0_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:a0d9cb4038f92e3a4e0b88eb7f8cb0c3a910a209287ea2a1df03b685ab21e124_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:b4e8c9f93db8c010e66752505bb16898201e00df040c421811381b9146a64a84_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:145b98c302bf402e92ec10bd57aec65a4bc412b4ecc84c79ff40fb1f06fe6ffa_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:3f99115f04ecdda40b64a297602563e9b148d75a6635456704f966c6f7f2e186_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:5b104b6c719263dbc8ed922d615acbe9dc5d06e4e74b27c04973fdb297eec0a4_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:fc825d9710b24ffd0b64288e6f14d9df4e2cd25c24b15c4abba926837be7fe5a_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:14ed60d1a4feff1402052e67f0d5dd0e8b0e385e507e1c4a9287467a4c714d67_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:66ba9bb065efa5f22e41d67865d48bc52f9efe070f4efc0a759fbc344e5c0212_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:a63ff7f7998afa696a5609aa8c7d241880a80cc50bccb50cbc2ff77c84d6a51b_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:d8881feacda4628cbe441bda5ad2e02f6239cf969b1a2951c1d60bdbd320ca3d_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:155885f184ad475c5a0a1f00b04fe4faacb3fa6f790e664384ee4e744fcac5f3_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:3f3f70bed536434e03c7034ae3cc59c4e57e400fd2d820c4b4efb21657d0b1b3_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:836b741f4c2bfe73deb7a7bf90eed048938b0315527bd3768ca5192dd3828cd1_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:e8b56c816998bf417d58d7585dfb8d9b872db450884bea471de9cdf71033bab5_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:5107f5d1c8d3b2764220891c8b1b11a4841b7c4a57c439276e369a869bba297b_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:e226d8250a54e78fc1a2d35789b77e6cc21114db5308b7b3289fc21df80a1e80_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:e98cc409807f96e7f07e00ea19eacc5c550e223f5b61ee263c90556faefe22dc_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:f656ddc5d5c4e67117f78f8bb55e35b853b6f3f4c66fc0f3dc9f1c8f054dac74_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:295e2184a61c757361e07612fe5b498febff4d3bd54f1e4e49493905824e132d_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:29890751840322ea5840c510e8efc755a224b7eaf54ee67d7e13a251802a245b_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:475e680efddd7d444cbf92d03d319fb1674e070966d8e7aac49e569b23045b74_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:da35f30bf23aa959569dd64c146c36d685ace17be5459cadcfcfe1d081c7c59a_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/eda-controller-rhel9-operator@sha256:4cd7f91dfcac40ebada825431f875b7d24e97c888b6bb290c4805a9936c0d4f2_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- +89 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Avoid using archive-type projects (scm_type='archive') until the fix is applied. Use Git-based projects (scm_type='git') instead where possible, as these do not use the vulnerable extraction code path. 2. Ensure all archive source URLs use HTTPS with valid certificates to prevent man-in-the-middle attacks on archive downloads. 3. Only configure archive-type projects with sources from trusted, verified providers. 4. Restrict the ability to create and modify projects to trusted administrators. 5. In containerized deployments, review execution environment container configurations to minimize host volume mounts and ensure the extraction runs with minimal filesystem permissions. Workaround: There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Restrict the admin role on webhook-enabled job templates to trusted personnel who already have legitimate access to the associated Git credentials. 2. Use Git credentials with the minimum required scope (e.g., read-only access to the specific repository) to limit the impact of credential leakage. 3. Implement network egress filtering on the Automation Controller nodes to prevent outbound connections to non-allowlisted hosts. Block outbound connections to loopback (127.0.0.0/8), private (RFC1918), and link-local (169.254.0.0/16) address ranges. 4. Monitor for unusual outbound connections from the Controller node to unexpected destinations. 5. Rotate Git PAT credentials periodically and after any suspected compromise. Workaround: There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Restrict the ability to create and modify notification templates to trusted administrators who have legitimate need for this capability. 2. Implement network egress filtering on the Automation Controller nodes to block outbound connections to loopback (127.0.0.0/8), private (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and link-local (169.254.0.0/16) address ranges. 3. Monitor notification template configurations for URLs pointing to internal or unusual addresses. 4. Avoid configuring sensitive credentials (Basic Auth, Grafana API keys) in notification templates until the fix is applied. Use notification backends that do not require credentials where possible. 5. Review and audit existing notification templates for URLs pointing to internal services.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2026:59155
- externalhttps://access.redhat.com/security/cve/CVE-2025-62718
- externalhttps://access.redhat.com/security/cve/CVE-2025-69223
- externalhttps://access.redhat.com/security/cve/CVE-2025-69227
- externalhttps://access.redhat.com/security/cve/CVE-2025-69228
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-14257
- externalhttps://access.redhat.com/security/cve/CVE-2026-15307
- externalhttps://access.redhat.com/security/cve/CVE-2026-1615
- externalhttps://access.redhat.com/security/cve/CVE-2026-44545
- externalhttps://access.redhat.com/security/cve/CVE-2026-44705
- externalhttps://access.redhat.com/security/cve/CVE-2026-59886
- externalhttps://access.redhat.com/security/cve/CVE-2026-67325
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-69243
- externalhttps://access.redhat.com/security/cve/CVE-2026-69244
- externalhttps://access.redhat.com/security/cve/CVE-2026-71364
- externalhttps://access.redhat.com/security/cve/CVE-2026-71365
- externalhttps://access.redhat.com/security/cve/CVE-2026-71366
- externalhttps://access.redhat.com/security/cve/CVE-2026-9595
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59155.json