Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Container Release Update
🔗 CVE IDs covered (29)
📋 Description
CVE-2025-57847 — ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions
CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
CVE-2026-15307 — django: Django: Remote code execution via GeoDjango spatial lookups
CVE-2026-42215 — GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
CVE-2026-42284 — GitPython: GitPython: Arbitrary code execution via improper validation of clone options
CVE-2026-44244 — GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href
CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing
CVE-2026-59893 — sqlparse: sqlparse: Denial of Service via inefficient SQL parsing
CVE-2026-67322 — gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL
CVE-2026-67323 — gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
CVE-2026-67325 — gitpython: GitPython: Command Injection via Git option prefix abbreviation
CVE-2026-71491 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping
CVE-2026-73620 — gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding
CVE-2026-73622 — gitpython: GitPython: Information disclosure via environment variable expansion in URL handling
CVE-2026-73623 — gitpython: GitPython: Remote Code Execution via malicious Git template
CVE-2026-73624 — gitpython: GitPython: Arbitrary File Overwrite via improper git option validation
CVE-2026-73625 — gitpython: GitPython: Remote Code Execution via kwarg value smuggling
CVE-2026-76218 — gitpython: GitPython: Remote Code Execution via malicious Git hooks
CVE-2026-76219 — gitpython: GitPython: Arbitrary File Overwrite via git read-tree option injection
CVE-2026-76220 — gitpython: GitPython: Arbitrary command execution via crafted kwargs
CVE-2026-76221 — gitpython: GitPython: Arbitrary code execution via config-name injection
CVE-2026-76222 — gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names
CVE-2026-78676 — gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection
CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function
CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization
CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing
CVE-2026-85393 — node-forge: node-forge: Signature forgery vulnerability in RSA PKCS#1 v1.5 verification
CVE-2026-87817 — GitPython: GitPython: Remote Code Execution via Git directory impersonation
🎯 Affected products103
- Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:1c158a694a145def13454923bf700b18bb1f3aa6d429f6d61fd79da47a673518_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:2de1b3a95d893cfe8400a1e38554411323b69463cca279f6e6989d3f88576423_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:82fae554165d7ad020ea49411c396888b7c71de7ab6d6e6d0e4e79ef1c267cb6_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/aap-must-gather-rhel8@sha256:f865a80fefce9a1ca8a3c0d50414bd6e1588491ca0149ad703b729c18d15b273_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:4591385f6b3541e789ef37a009b8ee15074f02a84abbfb56605eff3a88dd665c_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:46d58c18a492c1b3eb924ed7255cf127f12d8987b5e01cf6a6ca5a9d1f965c86_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:bc901dcc7a8b44cccd50e2b89819f3fd5b6268fe994597ad79034b0147204c4b_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-builder-rhel8@sha256:f2a1c222aa2d2b07968478795e2f8cfd2065e5fce2e301cc14060d96464ae9ea_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:53cb2cfa28b2b72bb02be626589a60c71a29117155be28ef049f796d6b7516cc_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:b2b28122ac45ae911dd0e7f5c0ce6dd5c2652c5ae9869e84d80ec55e2672aa09_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:da42d178ba498149ea830de8a072c5b8363f3639bcd35f8af00b29b3ef32d266_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-dev-tools-rhel8@sha256:e4071ba865cac4269448c0eb56e7f50a7692d8742b01c172332d2b8d830a9942_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:0e9846d8214c98b0bfda06501d6fc23cfd79f10a33fe91d44364abaf3915dda6_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:232e2db891cc3920c1b7ac86b603975c16ee831a1cbd03cca518b37de11f804c_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:31933d4c7488b282e963f54ba940d99626791af7c97b1ce0075df18a6b8d60ac_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-base-rhel8@sha256:d4ad8aeb66cd2dbbdcddbcb00fb06c82c6a415e4b89646230a054e812692a093_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:49c5fa5fc74156f880d1188696c5b45e6af2d8be73075243c12f7137de70849c_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:9f008479346ef483621efa7b4046c31f08ddededb0b64f40882cbca69b723e17_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:bdba7730a4db16cecffd316a46652b558fb5292a8b0968b559069ca4c586eee3_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/ansible-python-toolkit-rhel8@sha256:c920484578a2e15eabcff8740e47bcb5c9d0fcc3bc898269d7d5c8cc28a0ba7c_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:8c67c9ca23f49d2100dea1e0557aa754a03d84db5281ddc95e214fd48eda3498_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:efc9529b4f95c6e178fcd5f65fd074884778dee8399fc9f3cffc42809d55c7d1_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:f2c4db60d61d4e2dc7217ddad4b6ccfc98a19a8eefc0b347751e5f66f9d5881e_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8-operator@sha256:f37e1d120a0a83e8ccf5180e64135b0e56d647908e3df8886e85e94d7e86b0e7_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:0b9fbc7c08c52c1ff9bb444896b26e675ab2451fe83476e676c77c27e3bdf4be_s390x as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:3857cc4676afc5c9abed5951bc3d5a65bc64080521d6e6158ed0fb65b4e57cf8_ppc64le as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:51ff695326b344fe7dc742a7ade47b4aa1d2ff006182fc807a6f1e7992be0e18_amd64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/controller-rhel8@sha256:ca87db68209e21fa95a111be6c164a5293c0ff7f629029e01fb2e39437cf6f9e_arm64 as a component of Red Hat Ansible Automation Platform 2.5
- registry.redhat.io/ansible-automation-platform-25/de-minimal-rhel8@sha256:8173fc75f127c5986e88494411d10ecf4da9dd23cb8dcf83facae128f0c342d5_s390x as a component of Red Hat Ansible Automation Platform 2.5
- +73 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation. Workaround: To mitigate this issue, ensure that applications using GitPython's Repo.clone_from() method to clone from untrusted sources operate within a process environment that does not contain sensitive information as environment variables. Alternatively, implement strict validation and sanitization of all Git repository URLs before they are passed to Repo.clone_from() to prevent the inclusion of environment variable tokens. If the application is a service, a restart may be required for environment variable changes to take effect. Workaround: To mitigate the risk, ensure that applications utilizing GitPython are run within a sandboxed environment with minimal privileges. This limits the potential impact of arbitrary command execution or file truncation if an attacker successfully exploits the vulnerability through an application processing untrusted input. Review applications that interact with GitPython to ensure all input is properly sanitized and validated before being passed to methods such as Repo.archive(), git.ls_remote(), Repo.iter_commits(), or Repo.blame(). Workaround: Do not pass untrusted or attacker-influenced input as the template parameter (or other forwarded options) to GitPython's Repo.init. Upgrade to GitPython 3.1.58 or later, where the unsafe option forwarding is fixed. Workaround: Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed. Workaround: Do not pass untrusted or attacker-influenced keyword arguments to GitPython's guarded methods such as clone_from, and do not set split_single_char_options=False on untrusted input. Upgrade to GitPython 3.1.58 or later, where the check_unsafe_options bypass is fixed. Workaround: Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed. Workaround: There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests.
🔗 References (33)
- selfhttps://access.redhat.com/errata/RHSA-2026:71210
- externalhttps://access.redhat.com/security/cve/CVE-2025-57847
- externalhttps://access.redhat.com/security/cve/CVE-2025-66418
- externalhttps://access.redhat.com/security/cve/CVE-2026-15307
- externalhttps://access.redhat.com/security/cve/CVE-2026-42215
- externalhttps://access.redhat.com/security/cve/CVE-2026-42284
- externalhttps://access.redhat.com/security/cve/CVE-2026-44244
- externalhttps://access.redhat.com/security/cve/CVE-2026-49825
- externalhttps://access.redhat.com/security/cve/CVE-2026-54284
- externalhttps://access.redhat.com/security/cve/CVE-2026-59893
- externalhttps://access.redhat.com/security/cve/CVE-2026-67322
- externalhttps://access.redhat.com/security/cve/CVE-2026-67323
- externalhttps://access.redhat.com/security/cve/CVE-2026-67325
- externalhttps://access.redhat.com/security/cve/CVE-2026-71491
- externalhttps://access.redhat.com/security/cve/CVE-2026-73620
- externalhttps://access.redhat.com/security/cve/CVE-2026-73622
- externalhttps://access.redhat.com/security/cve/CVE-2026-73623
- externalhttps://access.redhat.com/security/cve/CVE-2026-73624
- externalhttps://access.redhat.com/security/cve/CVE-2026-73625
- externalhttps://access.redhat.com/security/cve/CVE-2026-76218
- externalhttps://access.redhat.com/security/cve/CVE-2026-76219
- externalhttps://access.redhat.com/security/cve/CVE-2026-76220
- externalhttps://access.redhat.com/security/cve/CVE-2026-76221
- externalhttps://access.redhat.com/security/cve/CVE-2026-76222
- externalhttps://access.redhat.com/security/cve/CVE-2026-78676
- externalhttps://access.redhat.com/security/cve/CVE-2026-82417
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/cve/CVE-2026-85393
- externalhttps://access.redhat.com/security/cve/CVE-2026-87817
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_71210.json