Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Container Release Update
🔗 CVE IDs covered (8)
📋 Description
CVE-2025-69223 — aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-15307 — django: Django: Remote code execution via GeoDjango spatial lookups CVE-2026-34070 — langchain: path traversal in legacy load_prompt functions in langchain-core CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values CVE-2026-67325 — gitpython: GitPython: Command Injection via Git option prefix abbreviation CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses
🎯 Affected products103
- Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:78b2bc546d36229b6caedb3fca261bf379355f6643b5e2cbde6bb0bd9df7fc21_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:7b014b4ca0f5ca5c5ff1c48245f3aac444f3abb1dae10bf26daedd21871f8ad9_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:9679ab3f0c719c48d77505970f641c7418ad80befa5ae3fd0d27eb4360927bf8_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:eea10492c8e505392212ae3e954424876b5f93c1b27bb8f00909be4b32312196_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:463a4d49f9c556d9f460f0cd4baef3becc987e6bf90ae1262834a2ff4610f889_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:86d2bfe950f111258fcb92a0fd6fb54e4a4ea74c60315007b867ff5ff0d339ed_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:91db97b0403b024b1a61a10f9c7f87032a0abeee45aaa2ec9491bafab0b5106f_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:9475f405368b95cdd92468131fb429f131c1a14027b70a62309bf392bb4b43af_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:88e40488753843edd3bf5204a361bdbd7cf54cd3aebae9cf20fc7006b584d2f2_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:cede00d94c4e82c7a061c24922968f08e7a6f985165a3d954b83f131c7b2984e_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:da52bd3eb5f3d92fa9b7b2f74c63fae328a906fb4ccc7e4224a0a22ac9349e2a_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:e8a5c95ff31895ce4f4acada04e6ee96d22359c7d24e9254c62340342169d388_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:43571e26f9f42d938257eefbf1da07e3534d0d0948f337f71593d3261b23a37c_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:932b8492b8b20ee2455e999089e8668d5ac4648d911ecda39ca54de44c3e4d25_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:b8482cbc57372d309703b38ed05458dea0f11cf8d3bffd98e96d09b5756c320c_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:cf9cbeee724f2ca0ee97af6501f011838125df4456c4a595a92be9a5df1dc98b_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:056a09aac6a4e01ea48e0ac22c3f582845177856443562c8268f482f96740cff_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:2489e322dbe1e4f27ddd29035ec69d38a58e5f1311fdb3ea70ed6be4e23692e7_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:9a04b9c62704ebfeaa7e0024ca35649bb4c4b84ee4660489152f6702e7fd6437_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:daeb49c843c24a4b30955b1092281087d928fcbdb741246a4b1f9406075176b1_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:2fabd1debdddc084d1d7f4c00ed5065ac1c4380d6898bfb22dad132b868386e7_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:5d0cfa56290410825677160e1455d1b75e237d2531b4182d3f0bb17fa804ad32_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:78d9268204b2178394391d0f3d1469836ae049aeafd2a2e2be42f8669387d1fe_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:892446270683107e2d644eb4fee6f1ca3e331d0b6a68134e194b0f572c65d6e4_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:0b2061b1022854ee90e7f35a381fa003f77dcb0f8e3dfc3461a6fe013133517f_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:48c44cd1cb6b9ab00557f05252cd3df0ca5de9524875c231aa31d4e070ba7ce4_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:5063bf9ee2f86674edbbb26d3701d4ceb5f564be6108c63f2b6c611408fc86e7_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:f3fdccec68a0cea216f2e5e467ee4f0fffc09dd15d40d89cb0198078be0100ea_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/de-minimal-rhel8@sha256:0771eff75ed8d73757ee3ad5a44c5ce5dc7401ed8521b382a339a19f3f4ce2e9_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- +73 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: As described in the statement section, the vulnerable methods are legacy APIs and their use should be avoided. To mitigate this issue, the dumpd, dumps, load and loads methods from langchain_core.load should be used, as they supersede the legacy API and provide a more secure serialization model. Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:59159
- externalhttps://access.redhat.com/security/cve/CVE-2025-69223
- externalhttps://access.redhat.com/security/cve/CVE-2026-14257
- externalhttps://access.redhat.com/security/cve/CVE-2026-15307
- externalhttps://access.redhat.com/security/cve/CVE-2026-34070
- externalhttps://access.redhat.com/security/cve/CVE-2026-59886
- externalhttps://access.redhat.com/security/cve/CVE-2026-67325
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-69244
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59159.json