RHSA-2026:73517HighCVSS 7.5
Red Hat Security Advisory: Ansible automation portal (Technology Preview)
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
🎯 Affected products3
- Red Hat Ansible Automation Platform 2.2
- registry.redhat.io/ansible-automation-platform/automation-portal-operator-bundle@sha256:b9870b58050f948fe7a9a166043c398fa4aba406c82a04e95eb8443fd7706b35_amd64 as a component of Red Hat Ansible Automation Platform 2.2
- registry.redhat.io/ansible-automation-platform/automation-portal-rhel9-operator@sha256:e99604a3de742690f246b4cbdac78bc434dca0abdd857b91a010324535f7a2bb_amd64 as a component of Red Hat Ansible Automation Platform 2.2
✅ Remediation
For more about Ansible Automation Portal Operator, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:73517
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_73517.json