Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update
🔗 CVE IDs covered (89)
📋 Description
CVE-2025-57847 — ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions
CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
CVE-2026-12564 — Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF
CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function
CVE-2026-15307 — django: Django: Remote code execution via GeoDjango spatial lookups
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options
CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href
CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin
CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.
CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-59877 — protobufjs: protobufjs: Denial of Service via crafted .proto schema
CVE-2026-59893 — sqlparse: sqlparse: Denial of Service via inefficient SQL parsing
CVE-2026-67322 — gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL
CVE-2026-67323 — gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
CVE-2026-67325 — gitpython: GitPython: Command Injection via Git option prefix abbreviation
CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL
CVE-2026-69244 — aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses
CVE-2026-71458 — automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enables cross-tenant resource name enumeration
CVE-2026-71459 — automation-controller: automation-controller-container: automation-controller: JobJobEventsChildrenSummary RBAC bypass exposes cross-tenant job event tree structure
CVE-2026-71460 — automation-controller: automation-controller-container: automation-controller: Any authenticated user reads Red Hat subscription/license details via /config/
CVE-2026-71462 — automation-controller: automation-controller-container: automation-controller: CUSTOM_VENV_PATH setting provides filesystem path-existence oracle on control pod
CVE-2026-71463 — automation-controller: automation-controller-container: automation-controller: Notification template Jinja whitelist bypass via conditional gating leaks tracebacks
CVE-2026-71464 — automation-controller: automation-controller-container: automation-controller: Schedule and WorkflowJobTemplateNode scm_branch prompt bypasses leading-dash git-argument guard
CVE-2026-71465 — automation-controller: automation-controller-container: automation-controller: Ad-hoc command limit field allows CLI argument injection into ansible executable
CVE-2026-71491 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping
CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow
CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding
CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling
CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template
CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation
CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling
CVE-2026-75884 — awx: awx: Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups
CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding
CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization
CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization
CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects
CVE-2026-76218 — gitpython: GitPython: Remote Code Execution via malicious Git hooks
CVE-2026-76219 — gitpython: GitPython: Arbitrary File Overwrite via git read-tree option injection
CVE-2026-76220 — gitpython: GitPython: Arbitrary command execution via crafted kwargs
CVE-2026-76221 — gitpython: GitPython: Arbitrary code execution via config-name injection
CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names
CVE-2026-78676 — gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection
CVE-2026-78679 — GitPython: GitPython: Arbitrary file read via TagReference.create()
CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function
CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization
CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing
CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies
CVE-2026-84470 — automation-controller: automation-controller-container: automation-controller/AWX: Bulk Job Launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass
CVE-2026-84474 — automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and X-Forwarded-For spoofing of provisioning-callback host match
CVE-2026-84486 — automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (AllowAny, routed without DEBUG guard) allow advisory-lock starvation of job dispatch (DoS)
CVE-2026-84499 — automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via Schedule/WorkflowJobTemplateNode survey min/max validation error message
CVE-2026-84502 — automation-controller: automation-controller-container: automation-controller: Project scm_url argument injection into git ls-remote --upload-pack yields RCE on the controller-task control-plane pod
CVE-2026-84638 — automation-controller: automation-controller-container: automation-controller: instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) instance groups and privilege escalation to control-plane code execution
CVE-2026-84643 — automation-controller: automation-controller-container: automation-controller: missing use_role authorization on the project signature validation credential foreign key allows a project administrator to bind and use another organization's credential cross-tenant
CVE-2026-84644 — automation-controller-container: automation-controller: automation-controller: server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the controller web process)
CVE-2026-84679 — automation-controller: automation-controller-container: automation-controller: the AWX_TASK_ENV setting applies arbitrary environment variables to the control-plane web and task processes, enabling TLS interception of external credentials and code execution
CVE-2026-84680 — automation-controller: automation-controller-container: automation-controller: organization galaxy credential attachment checks only read permission on the credential, allowing an organization admin with read-only visibility to bind and server-side-use another tenant's Automation Hub API token
CVE-2026-84683 — automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout HTML view via ANSI OSC 8 hyperlink sequences (javascript: anchor) enabling session takeover
CVE-2026-84684 — automation-controller: automation-controller-container: automation-controller: constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands against them
CVE-2026-84686 — automation-controller: automation-controller-container: automation-controller: notification template password fields can be decrypted by a notification-template administrator by replaying encrypted values across subfields, exposing plaintext Slack, PagerDuty, Twilio, AWS SNS and Grafana credentials
CVE-2026-84689 — automation-controller: automation-controller-container: automation-controller: bulk job launch allows setting a workflow node's job reference to an arbitrary unified job, enabling a low-privileged user to cancel and read metadata of jobs in other organizations
CVE-2026-84691 — automation-controller: automation-controller-container: automation-controller: format string injection in the API 4XX error log setting discloses Django SECRET_KEY and database credentials to an administrator
CVE-2026-84692 — automation-controller: automation-controller-container: automation-controller: workflow job template node execute permission check bypassed by creating a node with a null unified_job_template and then patching it, allowing a single workflow-admin to execute any other tenant's job template with the victim's credentials (cross-tenant privilege escalation)
CVE-2026-84703 — automation-controller: automation-controller-container: automation-controller: execution environment credential foreign key is not use-permission checked, allowing an organization execution-environment admin to bind and disclose another organization's container registry credential (cross-tenant credential disclosure)
CVE-2026-84706 — automation-controller: automation-controller-container: automation-controller: Credential Type env-injector deny-list omits process-hijacking variables (BASH_ENV/LD_PRELOAD) allowing code execution in the execution environment
CVE-2026-84707 — automation-controller: automation-controller-container: automation-controller: host_filter SmartFilter ORM traversal exposes JobEvent/AdHocCommandEvent event_data and stdout to users without permission on the job, enabling blind character-by-character extraction of job output (cross-tenant information disclosure)
CVE-2026-84708 — automation-controller: automation-controller-container: automation-controller: container group pod_spec_override mints the automation-controller ServiceAccount token and mounts control-plane namespace secrets into job pods, bypassing automountServiceAccountToken:false (control-plane secret and identity compromise)
CVE-2026-84709 — automation-controller: automation-controller: CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption (denial of service) and an unhandled-exception (500) via /api/controller/v2/credential_types/
CVE-2026-84711 — automation-controller: automation-controller: Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials on control-plane deployments) leading to full AAP and Kubernetes-namespace compromise
CVE-2026-84712 — automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership
CVE-2026-84714 — automation-controller: automation-controller: incomplete sanitize_jinja() regex allows Jinja template injection into ad-hoc module_args, Machine-credential fields, and Host names, reaching ansible-core templating in the execution environment
CVE-2026-84716 — automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-CA certificates for caller-chosen (and case-variant impersonating) hostnames
CVE-2026-84717 — automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in Bitbucket Data Center webhook receiver enumerates webhook-enabled job templates
CVE-2026-84718 — automation-controller: automation-controller: client IP spoofing in audit/access logs via unrestricted X-Forwarded-For trust
CVE-2026-84719 — automation-controller: automation-controller: WorkflowJobTemplate /copy/ deep-copy sanitizer omits instance_groups authorization (InstanceGroup use_role bypass to control-plane)
CVE-2026-84720 — automation-controller: automation-controller: WorkflowJobNode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via ORM-traversal count-oracle
CVE-2026-84724 — automation-controller: automation-controller: SystemJob extra_vars.days argument injection into uncontainerized control-plane awx-manage process
CVE-2026-85393 — node-forge: node-forge: Signature forgery vulnerability in RSA PKCS#1 v1.5 verification
CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation
🎯 Affected products119
- Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:1302191705838f29da44d8b812bf03b5d7806c6e31801e99e73f1254086357ee_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:143d71b4dabcee7cecf7abbd9c2bdab26eb5267c052f58cb8976a8d67596e528_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:b8900562660beab21e4b54533b7375711b21de6b96cd98380e487d5856ed9581_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:e8c9d372f5d1a704fa3fe2509d5892ef7498d639613b5bc18f8576749abff6a6_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:1b1009dd9d927bfb8e9f9b2eb597a1d2a3d5041686a30b59d7a970aac489676f_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:3194073a9f306d03829db98cfdafefa5c27f6c0890329082deb0b5f9b319925b_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:cdd7130fb02dc86ba8e3c72b3ab600e597e62389f8c08ee05e41a7a80f019ab2_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:fee9bbd62baced2222ade18bbae137ff8090077532119ea2f04e5efa52833838_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:b1dd010b857542b726300c89bbc462f1e3e5bb97e3e2d86f28697d49498aeb92_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:d783b3fa3daea76915743db173232ae806c27df829c235758f31fead509cb185_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:ebf06d5e07222b31d3baa9547b7c67d85e450696ae153e37626de960172ee2a4_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:eed996dbd7eca7715adb3ad61e61ff312cde487fe283b926bda518c12d444cb1_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:46266caee7c1bb20a85913132c482d4669b494f6b1f2f613afa13a66a6ea9e59_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:8557c6b4277961e12ba1d66932883084832a09081e5f3f9b7e8d0cddaa315a7c_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:d706ebf55a040276420efd72944a6a5b572041b15d346542674f4b7469b49781_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:e659700870bb51c0cad9d77bc698e20dc1b29704ae344a6a6c4f297fb07aa8af_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:0ea5754e6baa9da37abc43777bd9a05db5815454fc2949a8909a3e2aefc7a039_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:4cf288cd1d881eb5cecff0652678d92d3415e5ce673493897236175eaad83cec_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:7f06ccc449fcd34a7371313cf12b920af06e706b1fa259c471b5062c21f557f3_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:97bc35281e7490e2a07716c8cb7738d478af88e6cdcb5afc8d32505637be9365_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:240bc243cf8ea5dc0248b8a3cff3a2f57be56a2b5f60dfe5eb089e9a1676f9ba_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:7fed647525411bcfd9fe97e76e981a6de09be9e14bc0abb8898453726a9562f3_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:8299442c93457f21581aeac45279614b07052f1e8fad46cec7bed74d7d11689b_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:f11cf8cee7cf84c925f8eee070bf768bfc3fa7fbec88765403b9b270f9b97ce6_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:15e544936ada4deb4addd6d6527afa18945fc292e859a934050eef3378fc2468_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:76f471dbd0ef7629eb468cab75efbf1a9b2794994e50a1718289ac386666fb7a_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:a98424c9fb19670afdeb0880f4fb5f8d931e836b84bba074b4a174ca7f2302c1_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:f74b77ee8b2448631113eed28b53d9dd50829cfc91df94da1da7d890664c89bc_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/eda-controller-rhel9-operator@sha256:0ad74aa9b7435051686a5244d747e52bef0054a462ff0a2a72c218f14e4370f0_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- +89 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: The following practices would help for avoiding exposure and mitigate this flaw: - Restrict network egress from controller pods using Kubernetes NetworkPolicy to prevent outbound connections to untrusted destinations. Only allow connections to known Vault server endpoints. - Review and restrict the RBAC permissions of the automation-controller service account to follow the principle of least privilege. Remove unnecessary secret read access. - In AAP Cloud environments, audit credential-creation activity for suspicious HashiCorp Vault credentials with external or unusual URLs. - Monitor Kubernetes audit logs for unexpected API calls using the automation-controller service account, particularly secret reads and pod operations from EE pods. - Rotate the automation-controller service account token if unauthorized access is suspected. - Consider restricting the "create credential" privilege to only trusted administrators until the fix is available. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path. Workaround: Applications that only encode or decode protobuf messages using trusted schemas are not directly affected. Until patched protobufjs packages (7.6.5 / 8.6.6) are available, do not parse .proto schema text from untrusted sources via parse, Root.load, or Root.loadSync. Where untrusted schema input cannot be avoided, isolate .proto parsing in a dedicated worker thread or subprocess and enforce an explicit timeout so a non-returning parse cannot block the main event loop. Optional process-manager controls (for example systemd restart-on-failure, or CPU/cgroup limits) may reduce host-level impact or aid recovery for supervised services, but they do not fix the parser bug and are not a substitute for input isolation or applying the update. Workaround: To mitigate this issue, ensure that applications using GitPython's Repo.clone_from() method to clone from untrusted sources operate within a process environment that does not contain sensitive information as environment variables. Alternatively, implement strict validation and sanitization of all Git repository URLs before they are passed to Repo.clone_from() to prevent the inclusion of environment variable tokens. If the application is a service, a restart may be required for environment variable changes to take effect. Workaround: To mitigate the risk, ensure that applications utilizing GitPython are run within a sandboxed environment with minimal privileges. This limits the potential impact of arbitrary command execution or file truncation if an attacker successfully exploits the vulnerability through an application processing untrusted input. Review applications that interact with GitPython to ensure all input is properly sanitized and validated before being passed to methods such as Repo.archive(), git.ls_remote(), Repo.iter_commits(), or Repo.blame(). Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: Do not pass untrusted or attacker-influenced input as the template parameter (or other forwarded options) to GitPython's Repo.init. Upgrade to GitPython 3.1.58 or later, where the unsafe option forwarding is fixed. Workaround: Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed. Workaround: Do not pass untrusted or attacker-influenced keyword arguments to GitPython's guarded methods such as clone_from, and do not set split_single_char_options=False on untrusted input. Upgrade to GitPython 3.1.58 or later, where the check_unsafe_options bypass is fixed. Workaround: Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed. Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stri…
🔗 References (93)
- selfhttps://access.redhat.com/errata/RHSA-2026:71179
- externalhttps://access.redhat.com/security/cve/CVE-2025-57847
- externalhttps://access.redhat.com/security/cve/CVE-2025-66418
- externalhttps://access.redhat.com/security/cve/CVE-2026-12564
- externalhttps://access.redhat.com/security/cve/CVE-2026-14257
- externalhttps://access.redhat.com/security/cve/CVE-2026-15307
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-42215
- externalhttps://access.redhat.com/security/cve/CVE-2026-42284
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-44244
- externalhttps://access.redhat.com/security/cve/CVE-2026-49825
- externalhttps://access.redhat.com/security/cve/CVE-2026-53488
- externalhttps://access.redhat.com/security/cve/CVE-2026-53492
- externalhttps://access.redhat.com/security/cve/CVE-2026-54284
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-59877
- externalhttps://access.redhat.com/security/cve/CVE-2026-59893
- externalhttps://access.redhat.com/security/cve/CVE-2026-67322
- externalhttps://access.redhat.com/security/cve/CVE-2026-67323
- externalhttps://access.redhat.com/security/cve/CVE-2026-67325
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-69244
- externalhttps://access.redhat.com/security/cve/CVE-2026-71458
- externalhttps://access.redhat.com/security/cve/CVE-2026-71459
- externalhttps://access.redhat.com/security/cve/CVE-2026-71460
- externalhttps://access.redhat.com/security/cve/CVE-2026-71462
- externalhttps://access.redhat.com/security/cve/CVE-2026-71463
- externalhttps://access.redhat.com/security/cve/CVE-2026-71464
- externalhttps://access.redhat.com/security/cve/CVE-2026-71465
- externalhttps://access.redhat.com/security/cve/CVE-2026-71491
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73620
- externalhttps://access.redhat.com/security/cve/CVE-2026-73622
- externalhttps://access.redhat.com/security/cve/CVE-2026-73623
- externalhttps://access.redhat.com/security/cve/CVE-2026-73624
- externalhttps://access.redhat.com/security/cve/CVE-2026-73625
- externalhttps://access.redhat.com/security/cve/CVE-2026-75884
- externalhttps://access.redhat.com/security/cve/CVE-2026-75899
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-75975
- externalhttps://access.redhat.com/security/cve/CVE-2026-76172
- externalhttps://access.redhat.com/security/cve/CVE-2026-76218
- externalhttps://access.redhat.com/security/cve/CVE-2026-76219
- externalhttps://access.redhat.com/security/cve/CVE-2026-76220
- externalhttps://access.redhat.com/security/cve/CVE-2026-76221
- externalhttps://access.redhat.com/security/cve/CVE-2026-76222
- externalhttps://access.redhat.com/security/cve/CVE-2026-78676
- externalhttps://access.redhat.com/security/cve/CVE-2026-78679
- externalhttps://access.redhat.com/security/cve/CVE-2026-82417
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/cve/CVE-2026-84470
- externalhttps://access.redhat.com/security/cve/CVE-2026-84474
- externalhttps://access.redhat.com/security/cve/CVE-2026-84486
- externalhttps://access.redhat.com/security/cve/CVE-2026-84499
- externalhttps://access.redhat.com/security/cve/CVE-2026-84502
- externalhttps://access.redhat.com/security/cve/CVE-2026-84638
- externalhttps://access.redhat.com/security/cve/CVE-2026-84643
- externalhttps://access.redhat.com/security/cve/CVE-2026-84644
- externalhttps://access.redhat.com/security/cve/CVE-2026-84679
- externalhttps://access.redhat.com/security/cve/CVE-2026-84680
- externalhttps://access.redhat.com/security/cve/CVE-2026-84683
- externalhttps://access.redhat.com/security/cve/CVE-2026-84684
- externalhttps://access.redhat.com/security/cve/CVE-2026-84686
- externalhttps://access.redhat.com/security/cve/CVE-2026-84689
- externalhttps://access.redhat.com/security/cve/CVE-2026-84691
- externalhttps://access.redhat.com/security/cve/CVE-2026-84692
- externalhttps://access.redhat.com/security/cve/CVE-2026-84703
- externalhttps://access.redhat.com/security/cve/CVE-2026-84706
- externalhttps://access.redhat.com/security/cve/CVE-2026-84707
- externalhttps://access.redhat.com/security/cve/CVE-2026-84708
- externalhttps://access.redhat.com/security/cve/CVE-2026-84709
- externalhttps://access.redhat.com/security/cve/CVE-2026-84711
- externalhttps://access.redhat.com/security/cve/CVE-2026-84712
- externalhttps://access.redhat.com/security/cve/CVE-2026-84714
- externalhttps://access.redhat.com/security/cve/CVE-2026-84716
- externalhttps://access.redhat.com/security/cve/CVE-2026-84717
- externalhttps://access.redhat.com/security/cve/CVE-2026-84718
- externalhttps://access.redhat.com/security/cve/CVE-2026-84719
- externalhttps://access.redhat.com/security/cve/CVE-2026-84720
- externalhttps://access.redhat.com/security/cve/CVE-2026-84724
- externalhttps://access.redhat.com/security/cve/CVE-2026-85393
- externalhttps://access.redhat.com/security/cve/CVE-2026-87817
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_71179.json