Skip to main content
EPSS 0.2%top 94%

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update

0
High
Published: 10/28/2025 (10/28/2025, 19:18:04 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-platform-ui: tar-fs symlink validation bypass (CVE-2025-59343) * python3.11-django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682) * automation-eda-controller: Sensitive Internal Headers Disclosure in AAP EDA Event Streams (CVE-2025-9908) * automation-eda-controller: Event Stream Test Mode Exposes Sensitive Headers in AAP EDA (CVE-2025-9907) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Automation Platform * Fixes issue that prevents SAML and AzureAD authentication when local user accounts share the same email address (AAP-56518) * Updated error handling in the Authenticator form to match other forms in the Platform UI (AAP-56356) * Update autocomplete settings (AAP-55783) * Added a step in the subscription wizard that allows the user to configure automation analytics (AAP-55094) * Subscription credentials can no longer be viewed/edited from the system settings page (AAP-55014) * Fixed the permission list when creating a custom role and selecting the Automation Decisions project or credential types (AAP-54756) * Fixed an issue where the settings did not display "Red Hat" consistently in the API and UI (AAP-54276) * Fixed an issue where the Load More in authentication mapping role dropdown did not work (AAP-54049) * Fixed an issue where the decision environment dropdown displayed an empty dropdown when there are no decision environments available (AAP-53844) * Component label for Platform Auditor role was fixed to display all components (AAP-53551) * Topology layout and full screen mode were fixed (AAP-51106) * Empty strings are no longer displayed in the extra variables field on the Jobs > Details page (AAP-49448) * Added two new toggle options on the subscription wizard to allow for fetching subscriptions using basic authentication (AAP-47865) * Fixed default execution environment selection in the automation settings page (AAP-39321) * automation-gateway has been updated to 2.6.20251022 * automation-gateway-proxy has been updated to 2.6.6-4 * automation-platform-ui has been updated to 2.6.2 * python3.11-django-ansible-base has been updated to 2.6.20251023 Automation controller * The metrics endpoint no longer returns duplicate metrics(AAP-56148) * Fixed Platform Auditor to view controller settings (AAP-55607) * Added support for Red Hat username and password for the subscription management API (AAP-54975) * Fixed system_administrator role creation race condition (AAP-54963) * Improved stability on long-running jobs, clusters under heavy load and network flakiness in receptor (AAP-53742) * Fixed an issue where the ansible.platform collection did not work with the default Red Hat Ansible Automation Platform credential type (AAP-41000) * automation-controller has been updated to 4.7.4 * receptor has been updated to 1.6.0 Automation hub * Fixed an issue where _ui/v2/ user detail displayed the data incorrectly (AAP-54260) * automation-hub has been updated to 4.11.2 * python3.11-galaxy-importer has been updated to 0.4.34 * python3.11-galaxy-ng has been updated to 4.11.2 Event-Driven Ansible * automation-eda-controller has been updated to 1.2.1 Container-based Ansible Automation Platform * Fixed issue with the lightspeed containers configuration when running installation for the second time over the existing AAP (AAP-56263) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55180) * Implemented ansible-core version validation (AAP-54932) * containerized installer setup has been updated to 2.6-2 RPM-based Ansible Automation Platform * Fixed an issue where setting automationgateway_disable_https=false resulted in install failure (AAP-55466) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55183) * Fixed an issue where RESOURCE_KEY SECRET_KEY was not updated when restoring from a different environment (AAP-54942) * Fixed an issue where EDA DE credentials failed to populate on initial install (AAP-54519) * Fixed an issue where automation gateway's envoy.log did not receive logs after it was rotated (AAP-51779) * ansible-automation-platform-installer and installer setup have been updated to 2.6-2 Additional changes * Updated an

Affected software

Affected versions
>=2.6 <2.6.20251022>=2.5 <2.5.9999Red HatRed Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.6amd64registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:dae29680daff4810413849c1458c08d1d2bb6a07074cbd4c1eccacd109b9374c_amd64Red Hat Ansible Automation Platform 2.6 for RHEL 9Red Hat Ansible Automation Platform 2.5registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:fb284b670f3c4c28ac3bcc6a16d20db5ec38165750baf6a03f1d3b7cc316027f_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 20:21:00 UTC

Technical Analysis

This security advisory from Red Hat addresses multiple vulnerabilities in Red Hat Ansible Automation Platform 2.5 and 2.6, including CVE-2025-9907 which involves exposure of sensitive headers in the event-driven Ansible (EDA) event streams. Other fixes include a tar-fs symlink validation bypass (CVE-2025-59343) and a potential partial directory traversal in python3.11-django (CVE-2025-59682). The vulnerabilities span several CWE categories such as CWE-200 (Information Exposure), CWE-22 (Path Traversal), CWE-89 (SQL Injection), among others. Red Hat has released updated packages and container images that fix these issues, along with other improvements to authentication, role permissions, and system stability. The advisory explicitly lists affected versions and provides detailed remediation steps.

Potential Impact

The vulnerabilities allow unauthorized disclosure of sensitive internal headers in event streams, potential directory traversal, and symlink validation bypasses which could lead to information exposure and possibly other impacts depending on the environment. These issues could compromise confidentiality and integrity of automation workflows managed by the platform. No known exploits in the wild have been reported at the time of the advisory. The severity is rated as high/important by Red Hat.

Mitigation Recommendations

Red Hat has released official updates for Ansible Automation Platform 2.6 (fixed in version 2.6.20251022) and 2.5 container images that address these vulnerabilities. Users should apply all relevant errata and update to the fixed versions as per Red Hat's guidance. The vendor advisory provides detailed instructions for upgrading and applying patches. No additional mitigation steps beyond applying the official updates are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:19201
Cve Count
4
Additional Cves
["CVE-2025-9908","CVE-2025-59343","CVE-2025-59682"]
State
PUBLISHED

Threat ID: 6a1f4e87e29bf47b50080e73

Added to database: 06/02/2026, 21:43:35 UTC

Last enriched: 08/13/2026, 20:21:00 UTC

Last updated: 09/10/2026, 22:01:54 UTC

Views: 112

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses