Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.5%top 62%

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update

0
High
Published: 01/28/2026 (01/28/2026, 15:32:13 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: Django: Algorithmic complexity in XML Deserializer leads to denial of service (CVE-2025-64460) * automation-controller: urllib3 Streaming API improperly handles highly compressed data (CVE-2025-66471) * automation-controller: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb (CVE-2025-69223) * receptor: Excessive resource consumption when printing error string for host certificate validation in crypto/x509 (CVE-2025-61729) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included for Automation controller: * Restored the usage of system_tracking_logger (AAP-60506) * Fixed issue where jobs from other template sometimes appeared on template jobs page (AAP-59615) * Fixed the UI to display more than 25 input inventories in constructed inventories detail/edit form (AAP-59568) * Reduced number of API calls while scrolling through job output (AAP-58255) * automation-controller has been updated to 4.5.30 * receptor has been updated to 1.6.3

Affected software

Affected versions
>=2.4.0 <2.4.30Red HatRed Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.4 for RHEL 8

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 17:13:04 UTC

Technical Analysis

This advisory covers four security vulnerabilities in Red Hat Ansible Automation Platform 2.4. CVE-2025-64460 is an algorithmic complexity vulnerability in Django's XML deserializer that can lead to denial of service. CVE-2025-66471 involves urllib3's Streaming API improperly handling highly compressed data, potentially causing resource exhaustion. CVE-2025-69223 affects AIOHTTP's HTTP Parser auto_decompress feature, making it vulnerable to zip bomb attacks. CVE-2025-61729 concerns receptor's excessive resource consumption when printing error strings related to host certificate validation in crypto/x509. Red Hat has issued fixes in automation-controller version 4.5.30 and receptor version 1.6.3 to mitigate these vulnerabilities.

Potential Impact

The vulnerabilities can cause denial of service conditions through resource exhaustion or excessive resource consumption in affected components of the Ansible Automation Platform. This may disrupt automation workflows and impact availability of the automation services. There is no indication of code execution or data breach from these issues. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released updated packages automation-controller 4.5.30 and receptor 1.6.3 that address these vulnerabilities. Users of Red Hat Ansible Automation Platform 2.4 should apply these updates promptly following Red Hat's official documentation. No additional mitigations are specified by the vendor. Patch status is confirmed by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:1497
Cve Count
4
Additional Cves
["CVE-2025-64460","CVE-2025-66471","CVE-2025-69223"]
Cvss Version
null

Threat ID: 6a160971e29bf47b50639edd

Added to database: 05/26/2026, 20:58:25 UTC

Last enriched: 08/17/2026, 17:13:04 UTC

Last updated: 08/31/2026, 22:52:07 UTC

Views: 106

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses