Skip to main content
EPSS 0.5%top 60%

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update

0
High
Published: 07/20/2026 (07/20/2026, 18:19:51 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section.

Affected software

Affected versions
Red HatRed Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.6amd64registry.redhat.io/ansible-automation-platform-26/mcp-tools-rhel9@sha256:09b95ff35ae5c1b2c356f7506d4e8283cb0b69b8b5a130bf9d6c31e6bfc04932_amd64Red Hat Developer HubRed Hat Developer Hub 1.10registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:61883f5228095e3a3fd5b7daf60e29a5ffd053844f8661a2b5282a77c086dc02_amd64Red Hat Ansible Automation Platform 2.7registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:980c9848e4fef2d12c7282bad4554326d5f779e26af1dd0e0b04a573457b0dff_amd64multicluster engine for Kubernetesmulticluster engine for Kubernetes 2.11registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:4a7618d5db8ebb99bf7b4e3ad04094af43c9e6df1786461b47ec073dcc9cd377_amd64Red Hat QuayRed Hat Quay 3.16registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:892c8bae38073747321083d3cb6fe0fbd2b1ab6547f8bbbf42f5cd6eac895ed1_amd64Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.22ppc64leregistry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:08a956967c886e92d45a043bae801f3224d52d4e17746991230f17d2dcd38643_ppc64leRed Hat SatelliteRed Hat Satellite 6.18registry.redhat.io/satellite/iop-vulnerability-frontend-rhel9@sha256:6af0a58a2e872d0e59c61277af795867da59174f53969162e162e9acb4ca9c35_amd64Red Hat Ansible Automation Platform 2.6 for RHEL 9srcRed Hat OpenShift Container Platform 4.2registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:6c73f4ebf9ce875efeff6952296e240937e2b97a473416093db2b00fe57abc32_amd64Red Hat OpenShift Container Platform 4.21arm64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:8767026aa89aaa77b06c0b1387bbe677817ff7fb1e965d025e91399dd885959b_arm64Red Hat Quay 3.17registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:2c80074a85868ebbc3070868904dd35fd0c6e383f790915078f34c0a877987b5_amd64Red Hat Quay 3.9registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:97f36276e98ba3d93763bfe7c921bca2f41ee4f7fbdbe6052aea28122f38259b_amd64Red Hat JBoss Data GridRed Hat Data Grid 8.6.2Red Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.21registry.redhat.io/odf4/cephcsi-rhel9@sha256:83237116629c7b841876eeb0ee44a1b5d2aeb367e4f45378cf826ebcdb252fc8_amd64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:d8c480851f5eb9c2c335b75f4ca04241c1aa595298dcd15804dc2b75373af365_amd64Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:14d639afc36e492504ee9ee0079f72410105773d20420a9bdcc68784f95e79e0_amd64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:3bdf1304fbd9282b90946b1d7f88ccec7b7572dc38ab3acc60373d105934e8c7_amd64registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:d090b565d5d2933ae453eb87c34a2ebb00e09b1b00334a98c771e465dbcea42e_amd64registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:83b84d657ff2bca4cc7b10d2adf69ed585acedbf4c2221df6c66b386e97d964e_ppc64leRed Hat OpenShift Container Platform 4.20Red Hat Quay 3.12registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:876b89b047656b208af0f57881bb7ae351f53c2f875675686e5b334b74d2ac2b_amd64Red Hat Quay 3.1registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:5040540e6ed9126958497b0b12d1d119eb06f445ca0edeb0f823880d5c936567_amd64registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:d360584da77d3ba36577171c971e0c751649f43e76ac560586bf2e3ee5e2ff76_amd64Red Hat Hardened Imagesaarch64grafana13-1-main@aarch64>=3.0.0 <3.1.2<2.4.1registry.redhat.io/openshift4/ose-tests-rhel9@sha256:aa04c70dae212af46c5f2b0bd4f845a26aa6b8a163ef5a82591e1228b2c16553_ppc64le

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 00:29:45 UTC

Technical Analysis

The multicluster engine for Kubernetes v2.11.0 release addresses several security vulnerabilities, including CVE-2026-29181, a denial of service vulnerability in OpenTelemetry-Go. This flaw allows a remote attacker to send multiple crafted 'baggage' HTTP header lines, causing independent parsing and aggregation that leads to amplified CPU and memory resource consumption. This can render services unavailable in environments managing multiple Kubernetes clusters. Red Hat has released updated images and documentation for installation of fixed versions. The advisory references multiple CVEs and a broad set of CWEs related to resource exhaustion, improper input validation, and other security weaknesses. Patch availability is confirmed by Red Hat's advisory.

Potential Impact

Exploitation of the OpenTelemetry-Go vulnerability (CVE-2026-29181) can cause denial of service by exhausting CPU and memory resources, potentially disrupting the centralized management of Kubernetes clusters. This impact is significant in multi-cluster environments where the multicluster engine is used. Other vulnerabilities addressed in this release may also affect system stability and security, but specific impacts beyond the denial of service are not detailed in the provided data.

Mitigation Recommendations

A patch is available for the multicluster engine for Kubernetes v2.11.0 and related Red Hat products. Users should apply the updated images and follow Red Hat's installation documentation to remediate the vulnerabilities. No vendor advisory indicates that no action is required or that the issue is already mitigated without patching. Therefore, updating to the fixed versions is the recommended mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:25271
Cve Count
9
Additional Cves
["CVE-2026-29181","CVE-2026-40895","CVE-2026-42033","CVE-2026-42035","CVE-2026-42039","CVE-2026-42041","CVE-2026-42043","CVE-2026-42044"]

Threat ID: 6a2af14f815e7002b814edc3

Added to database: 06/11/2026, 17:33:03 UTC

Last enriched: 08/15/2026, 00:29:45 UTC

Last updated: 09/14/2026, 22:01:36 UTC

Views: 224

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:25271https://access.redhat.com/security/cve/CVE-2026-29181https://access.redhat.com/security/cve/CVE-2026-40895https://access.redhat.com/security/cve/CVE-2026-42033https://access.redhat.com/security/cve/CVE-2026-42035https://access.redhat.com/security/cve/CVE-2026-42039https://access.redhat.com/security/cve/CVE-2026-42041https://access.redhat.com/security/cve/CVE-2026-42043https://access.redhat.com/security/cve/CVE-2026-42044https://access.redhat.com/security/cve/CVE-2026-6322https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:26225https://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/indexhttps://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-27904https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-41680https://access.redhat.com/security/cve/CVE-2026-9277https://catalog.redhat.com/software/containers/searchhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellitehttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satelliteCanonical URLhttps://access.redhat.com/errata/RHSA-2026:28571https://access.redhat.com/security/cve/CVE-2026-10143https://access.redhat.com/security/cve/CVE-2026-44432https://access.redhat.com/security/cve/CVE-2026-44496https://access.redhat.com/security/cve/CVE-2026-48526Canonical URLhttps://access.redhat.com/errata/RHSA-2026:29800https://access.redhat.com/security/cve/CVE-2026-44494Canonical URLhttps://access.redhat.com/errata/RHSA-2026:41066https://access.redhat.com/security/cve/CVE-2026-12143https://access.redhat.com/security/cve/CVE-2026-13676https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32591https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-39828https://access.redhat.com/security/cve/CVE-2026-39829https://access.redhat.com/security/cve/CVE-2026-39830https://access.redhat.com/security/cve/CVE-2026-39831https://access.redhat.com/security/cve/CVE-2026-39832https://access.redhat.com/security/cve/CVE-2026-39835https://access.redhat.com/security/cve/CVE-2026-42151https://access.redhat.com/security/cve/CVE-2026-42154https://access.redhat.com/security/cve/CVE-2026-42499https://access.redhat.com/security/cve/CVE-2026-42504https://access.redhat.com/security/cve/CVE-2026-42508https://access.redhat.com/errata/RHSA-2026:41951https://access.redhat.com/security/updates/classification/#important246668424679272477213247721924772202477231248278524841152484116248412324841242486697248671624879372487938248794224879432487947https://access.redhat.com/errata/RHSA-2026:36754https://access.redhat.com/security/cve/CVE-2026-12151https://access.redhat.com/security/cve/CVE-2026-24781https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-42338https://access.redhat.com/security/cve/CVE-2026-44486https://access.redhat.com/security/cve/CVE-2026-44487https://access.redhat.com/security/cve/CVE-2026-44488https://access.redhat.com/security/cve/CVE-2026-44492https://access.redhat.com/security/cve/CVE-2026-44495https://access.redhat.com/security/cve/CVE-2026-45736https://access.redhat.com/security/cve/CVE-2026-47131https://access.redhat.com/security/cve/CVE-2026-47135https://access.redhat.com/security/cve/CVE-2026-47137https://access.redhat.com/security/cve/CVE-2026-47139https://access.redhat.com/errata/RHSA-2026:37628https://access.redhat.com/security/cve/CVE-2026-44293https://access.redhat.com/security/cve/CVE-2026-9595Canonical URLhttps://access.redhat.com/errata/RHSA-2026:34160https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updateshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade24497742461147246160624771042477154247716724827342487949Canonical URLhttps://access.redhat.com/errata/RHSA-2026:29834Canonical URLhttps://access.redhat.com/errata/RHSA-2026:42142https://access.redhat.com/security/cve/CVE-2026-12382https://access.redhat.com/security/cve/CVE-2026-12701https://access.redhat.com/security/cve/CVE-2026-27145https://access.redhat.com/security/cve/CVE-2026-42264https://access.redhat.com/security/cve/CVE-2026-42561https://access.redhat.com/security/cve/CVE-2026-48746https://access.redhat.com/security/cve/CVE-2026-54283https://access.redhat.com/errata/RHSA-2026:30076Canonical URLhttps://access.redhat.com/errata/RHSA-2026:33683Canonical URLhttps://access.redhat.com/errata/RHSA-2026:34374https://access.redhat.com/security/cve/CVE-2026-33154https://access.redhat.com/security/cve/CVE-2026-44431https://access.redhat.com/security/cve/CVE-2026-8643Canonical URLhttps://access.redhat.com/errata/RHSA-2026:34766https://access.redhat.com/security/cve/CVE-2026-35469Canonical URLhttps://access.redhat.com/errata/RHSA-2026:29796Canonical URLhttps://access.redhat.com/errata/RHSA-2026:34770Canonical URLReference 128Reference 129Reference 130Reference 131Reference 132Reference 133Reference 134Reference 135Reference 136Reference 137Reference 138Reference 139Reference 140https://access.redhat.com/errata/RHSA-2026:54395https://access.redhat.com/security/cve/CVE-2026-15927Canonical URLReference 144Reference 145https://access.redhat.com/errata/RHSA-2026:54555https://access.redhat.com/security/cve/CVE-2026-50236https://access.redhat.com/security/cve/CVE-2026-50237Canonical URLhttps://access.redhat.com/security/cve/CVE-2026-44188https://access.redhat.com/errata/RHSA-2026:56968https://access.redhat.com/security/cve/CVE-2026-34986https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60855https://access.redhat.com/security/cve/CVE-2026-75899https://access.redhat.com/security/cve/CVE-2026-75931https://access.redhat.com/security/cve/CVE-2026-75975https://access.redhat.com/security/cve/CVE-2026-76172https://images.redhat.com/Canonical URLReference 162Reference 163Reference 164Reference 165Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses