Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 1.0%top 41%

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update

0
High
Published: 03/06/2026 (03/06/2026, 16:36:31 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking (CVE-2026-24049) * automation-controller: pyasn1 has a DoS vulnerability in decoder (CVE-2026-23490) * automation-gateway: React Router vulnerable to XSS via Open Redirects (CVE-2026-22029) * python3.11-aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb (CVE-2025-69223) * python3.11-django: Django: SQL injection via crafted column aliases in QuerySet.order_by() (CVE-2026-1312) * python3.11-django: Django: SQL Injection via crafted column aliases (CVE-2026-1287) * python3.11-django: Django: Denial of Service via crafted HTML inputs (CVE-2026-1285) * python3.11-django: Django: SQL Injection via RasterField band index parameter (CVE-2026-1207) * python3.11-django: Django: Denial of Service via crafted request with duplicate headers (CVE-2025-14550) * python3.11-protobuf: Denial of Service in Python Protobuf (CVE-2026-0994) * receptor: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: * Python has been updated to 3.12 (AAP-56567) IMPORTANT: All users must download the latest version of the installer. Attempting to install or upgrade with a previous version of the installer could result in failure. Automation Platform * The OpenAPI gateway spec is now accurate for the legacy_auth endpoint (AAP-63422) * Fixed a bug that was preventing users from viewing complete survey question choices that contained a colon (AAP-66389) * Added source control branch option for inventory source form (AAP-63544) * automation-gateway has been updated to 2.5.20260225 Automation controller * Added token auth to 2.5 (AAP-65488) * Fixed the job list endpoint to no longer load the job artifacts, resulting in better performance (AAP-63221) * Enabled cross-organization credential sharing for teams. The changes were made in the legacy RBAC functionality (AAP-54804) * automation-controller has been updated to 4.6.26 Automation hub * Updated _ui/v2 endoints to properly enforce RBAC permissions (AAP-66638) * Added a static OpenAPI spec to galaxy that focuses the potential endpoints users can call (AAP-66417) * automation-hub has been updated to 4.10.12 Event-Driven Ansible * Overrode RQ's default heartbeat to call register_birth, allowing worker re-registration in case of worker disconnects from Redis, and also eliminating Ghost Workers. Also, bump rq version to 2.6.1, which is a more recent and stable release (AAP-56872) * automation-eda-controller has been updated to 1.1.16 Container-based Ansible Automation Platform * containerized installer setup has been updated to 2.5-22 RPM-based Ansible Automation Platform * Fixed an issue where restore was not properly generating SSL certificate for redis in cluster mode (AAP-60991) * ansible-automation-platform-installer and installer setup have been updated to 2.5-21 Additional changes: * ansible-core has been updated to 2.16.16 * All python3.11- prefixed rpms are replaced with python3.12- prefixed rpms

Affected software

Affected versions
Red HatRed Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.5 for RHEL 8

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 11:40:55 UTC

Technical Analysis

This advisory covers multiple security vulnerabilities in Red Hat Ansible Automation Platform 2.5, including CVE-2026-24049 (privilege escalation or arbitrary code execution via malicious wheel file unpacking in automation-controller), CVE-2026-23490 (denial of service in pyasn1 decoder), CVE-2026-22029 (XSS via open redirects in automation-gateway's React Router), CVE-2025-69223 (zip bomb vulnerability in aiohttp HTTP parser), several SQL injection and denial of service vulnerabilities in python3.11-django, CVE-2026-0994 (denial of service in python3.11-protobuf), and CVE-2025-61726 (memory exhaustion in receptor net/url query parsing). Red Hat has released updated packages including automation-controller 4.6.26, automation-gateway 2.5.20260225, automation-hub 4.10.12, and updated Python to 3.12. The update requires using the latest installer version to avoid installation or upgrade failures.

Potential Impact

The vulnerabilities collectively allow for privilege escalation, arbitrary code execution, denial of service, SQL injection, cross-site scripting, and memory exhaustion attacks within the Ansible Automation Platform environment. These issues could lead to unauthorized access, disruption of service, or compromise of automation workflows. The impact is rated as high by Red Hat Product Security.

Mitigation Recommendations

Red Hat has released an important security update for Ansible Automation Platform 2.5 that addresses all listed vulnerabilities. Users must download and apply the latest installer version to successfully upgrade and remediate these issues. The update includes updated components and a Python upgrade to version 3.12. Follow the official Red Hat advisory RHSA-2026:3959 and Ansible Automation Platform documentation for detailed update instructions. No additional mitigations are required beyond applying this official fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:3959
Cve Count
11
Additional Cves
["CVE-2025-61726","CVE-2025-69223","CVE-2026-0994","CVE-2026-1207","CVE-2026-1285","CVE-2026-1287","CVE-2026-1312","CVE-2026-22029","CVE-2026-23490","CVE-2026-24049"]
Cvss Version
null

Threat ID: 6a160964e29bf47b50629757

Added to database: 05/26/2026, 20:58:12 UTC

Last enriched: 07/30/2026, 11:40:55 UTC

Last updated: 07/31/2026, 19:30:14 UTC

Views: 126

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses