RHSA-2026:67279CriticalCVSS 9.6

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update

Published
September 14, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (30)

📋 Description

CVE-2025-57847 — ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions CVE-2026-12564 — Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-15307 — django: Django: Remote code execution via GeoDjango spatial lookups CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-59877 — protobufjs: protobufjs: Denial of Service via crafted .proto schema CVE-2026-59893 — sqlparse: sqlparse: Denial of Service via inefficient SQL parsing CVE-2026-67322 — gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL CVE-2026-67323 — gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options CVE-2026-67325 — gitpython: GitPython: Command Injection via Git option prefix abbreviation CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-69243 — aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses CVE-2026-71491 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing

🎯 Affected products63

  • Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/aap-must-gather-rhel9@sha256:8be5c9c538721b3990b29292f24874c45808157b7b137f4fbca1623384b2ab7a_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/aap-must-gather-rhel9@sha256:9777685f96b48dbf79f909e81befd536c7f6e0ce9786a32bcbdcb8ea8f87bc06_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-builder-rhel9@sha256:50d4b7e8980105bebb5e1f906c2b7bebe1a985c569da9c345db10092965f81d7_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-builder-rhel9@sha256:bc141ab6503aa96a9f7af3041ffbf97dfdf41389d2961b4d400ff21dea237fd4_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-dev-tools-rhel9@sha256:73f39232476752d8ed3b798810e2c4f8d763c0f16bace31c9df681635984e10b_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-dev-tools-rhel9@sha256:f39590e1919256a14694079f5b18c7eafd64957ea7295912b276e5e5c76c4d99_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-devspaces-rhel9@sha256:8b28277ad82fec3075cdb189718a72bfc060fc1869a34c48bbf04f3003dd4f25_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ansible-devspaces-rhel9@sha256:f64f6878e6106e898f68554284cf275a3c8f1e145f1a1a068cc5dfa7002c6a72_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9-operator@sha256:057d6c32355b432df4e1da3a5538abe7a36224a191c91bc2acbcbedd3cc16c48_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9-operator@sha256:7a1018e3e5e0eff5eb338fe1b7eb3fe1ff470c297a270b961d0415b1d2791603_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9@sha256:9983132bfd47c33f7fdd2cc01321073dad328782241bce2c732732af62d36269_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/controller-rhel9@sha256:b99a62cbdc10cab91527447c91e6ff490f446766d3485728872c4227db6b8dff_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-minimal-rhel9@sha256:6aa6754aa90ab1a32b95cfce4cd6034aa2588e66b57d3cbd7b3c2cdd50798a02_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-minimal-rhel9@sha256:74dc4ec17f34b98ef3a6b3540ab932f1243297c9ea8e04271f77b0f821eb0d31_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-supported-rhel9@sha256:4ba3c213f0f241ed4ddf87e5324fd97b91749e36bcbfb4accee9831fe6ca9fd1_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/de-supported-rhel9@sha256:6989919b221a7d127b9f6dfa095d77f9453f43655ff0996d333c22af0304dd0c_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9-operator@sha256:04698ef714b25d6d1da9646d8dad30fe5a0e3a33a595dbb469498fb4bba63923_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9-operator@sha256:5ef91d41574404f344d220da3bac407ba1cb6a5e0ef5488c99b1ae4e6a5f4ee8_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9@sha256:630c688ed64c4bd34e4ea9715a24c415a9e15cff3e8696a25757284645a785c3_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9@sha256:a7e67067716d87b77a265ec3c5f2c4b5fc735041f46224e2b80be4f2dc7cefb2_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-ui-rhel9@sha256:077998f95260e7be8fd8f29278c2e006e176aa8614ac1e55c0ecd304c797ea10_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/eda-controller-ui-rhel9@sha256:7aaf90f8c792aefec7fc70c421927f187c380a89f0de2c80bb76c4c743de442f_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:0ac29c4d6fdab1566a2072b03beba03ee03672c11dc5302b5e60d27205c551bc_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:700f66b260cbe711b672e6f69698042e5ea882fd5f41112ed02a9c71dd32c46a_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:cafa9404b685a8e4dd03b92f0cdeb1e2031a7cb07f76f0f8eb373cec7a0e0ce5_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-minimal-rhel9@sha256:d73c8c845b3f61f7347f34070c1cdc4e0a2384a94c3811cdd2837e33eac8b723_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-supported-rhel9@sha256:174af36c0aea5a194ce9207c1429ebf4708e6a7848451a005e8c91eba5d722db_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/ee-supported-rhel9@sha256:5eca59c3245b94baab5fe0bd0e271f87ae863e325860ebf79537222235b1bc28_amd64 as a component of Red Hat Ansible Automation Platform 2.7
  • registry.redhat.io/ansible-automation-platform-27/gateway-proxy-rhel9@sha256:6d9fe8f9111045c317378f12d15656c5bfcb27960823f71c8c1fb91b2207f1bc_arm64 as a component of Red Hat Ansible Automation Platform 2.7
  • +33 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.7#Upgrade Workaround: The following practices would help for avoiding exposure and mitigate this flaw: - Restrict network egress from controller pods using Kubernetes NetworkPolicy to prevent outbound connections to untrusted destinations. Only allow connections to known Vault server endpoints. - Review and restrict the RBAC permissions of the automation-controller service account to follow the principle of least privilege. Remove unnecessary secret read access. - In AAP Cloud environments, audit credential-creation activity for suspicious HashiCorp Vault credentials with external or unusual URLs. - Monitor Kubernetes audit logs for unexpected API calls using the automation-controller service account, particularly secret reads and pod operations from EE pods. - Rotate the automation-controller service account token if unauthorized access is suspected. - Consider restricting the "create credential" privilege to only trusted administrators until the fix is available. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: Applications that only encode or decode protobuf messages using trusted schemas are not directly affected. Until patched protobufjs packages (7.6.5 / 8.6.6) are available, do not parse .proto schema text from untrusted sources via parse, Root.load, or Root.loadSync. Where untrusted schema input cannot be avoided, isolate .proto parsing in a dedicated worker thread or subprocess and enforce an explicit timeout so a non-returning parse cannot block the main event loop. Optional process-manager controls (for example systemd restart-on-failure, or CPU/cgroup limits) may reduce host-level impact or aid recovery for supervised services, but they do not fix the parser bug and are not a substitute for input isolation or applying the update. Workaround: To mitigate this issue, ensure that applications using GitPython's Repo.clone_from() method to clone from untrusted sources operate within a process environment that does not contain sensitive information as environment variables. Alternatively, implement strict validation and sanitization of all Git repository URLs before they are passed to Repo.clone_from() to prevent the inclusion of environment variable tokens. If the application is a service, a restart may be required for environment variable changes to take effect. Workaround: To mitigate the risk, ensure that applications utilizing GitPython are run within a sandboxed environment with minimal privileges. This limits the potential impact of arbitrary command execution or file truncation if an attacker successfully exploits the vulnerability through an application processing untrusted input. Review applications that interact with GitPython to ensure all input is properly sanitized and validated before being passed to methods such as Repo.archive(), git.ls_remote(), Repo.iter_commits(), or Repo.blame(). Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.

🔗 References (34)