Threats Tagged 'cve-2025-4565'
View all threats tagged with 'cve-2025-4565'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-4565'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 03/06/2026, 11:24:38 UTC Added: 05/26/2026, 20:58:12 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: AIOHTTP HTTP Request/Response Smuggling (CVE-2025-53643) * automation-controller: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb (CVE-2025-69223) * automation-controller: Django: Algorithmic complexity in XML Deserializer leads to denial of service (CVE-2025-64460) * automation-controller: urllib3 Streaming API improperly handles highly compressed data (CVE-2025-66471) * python3.11-django: Algorithmic complexity in XML Deserializer leads to denial of service (CVE-2025-64460) * python3.11-protobuf: Unbounded recursion in Python Protobuf (CVE-2025-4565) * python3.11-urllib3: urllib3 Streaming API improperly handles highly compressed data (CVE-2025-66471) * receptor: Excessive resource consumption when printing error string for host certificate validation in crypto/x509 (CVE-2025-61729) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Automation Platform * Reduced cognitive complexity in _sync_user_superuser_flag (AAP-62771) * The FEATURE_GATEWAY_IPV6_USAGE_ENABLED feature flag has been removed and IPv6 support is enabled by default (AAP-61805) * Fixed an issue preventing gateway from working in a pure IPv4 single stack environment when IPv6 is enabled (AAP-60478) * Added dedicated aap.auth_audit logger with specialized formatters and handlers (AAP-60364) * Introduced new logs for authentication events (AAP-60364) * automation-gateway has been updated to 2.6.20260121 * python3.11-django-ansible-base has been updated to 2.6.20260121 Automation Platform UI * Page titles now reflect the current page content (AAP-61754) * Allow full search in resource dropdowns (AAP-57712) * Fixed an issue that occasionally showed a bad request status when navigating between different pages (AAP-56701) * Fixed filtering by name in Collections page (AAP-56529) * Fixed clear/browse button behavior in Client Certificate and Client Key (AAP-55296) * Fixed an issue where a Rulebook Activation in workers offline status could not be disabled or deleted (AAP-52714) * Fixed an issue where workflow job templates node credentials are missing after save for job template nodes that have a default credential that is promptable (AAP-52638) * Fixed an issue where the gateway UI reset the order of an auth mapping when the entity was edited by the user (AAP-52258) * Improves labels and descriptions for Authenticator Mappings details (AAP-51295) * Resolved an issue where controller unavailability rendered the entire AAP UI inaccessible (AAP-50106) * Fixed descriptions for Remotes and Remote Registries (AAP-49838) * Survey textarea "Default Answer" field now properly accepts newlines when pressing Enter (AAP-49820) * Fixed review page on Workflow Approval Nodes (AAP-49433) * Fixed editing of "Days of data to keep" value in management job schedules (AAP-48972) * Editing and saving credentials that use external credential lookup plugins (such as CyberArk) no longer fails with an error message (AAP-44813) * Fixed an issue where the SAML Service Provider extra configuration data field could not be cleared in the UI, as it would automatically reset to the default value (AAP-43661) * Resolved an issue where ad-hoc commands failed with a "Bad Request" error when using credentials configured with "Prompt on launch" for password fields (AAP-43603) * Updated modal warning message and layout when enabling a copied Rulebook Activation (AAP-42574) * automation-platform-ui has been updated to 2.6.5 Automation controller * Added runtime feature flags (AAP-62686) * automation-controller has been updated to 4.7.8 * receptor has been updated to 1.6.3 Automation hub * Autocomplete attribute added to the Automation Hub API password field (AAP-59910) * automation-hub has been updated to 4.11.5 * python3.11-galaxy-importer has been updated to 0.4.37 * python3.11-galaxy-ng has been updated to 4.11.5 * python3.11-pulpcore has been updated to 3.49.49 Event-Driven Ansible * Added x-ai-description field to the activation PATCH method (AAP-61969) * automation-eda-controller has been updated to 1.2.4 Container-based Ansible Automation Platform * Added lTLS support to lightspeed chatbot service (AAP-60900) * system-prompt was optimized for granite and openai models (AAP-60898) * Added ipv6 support (AAP-60532) * Fixed an issue w Join the discussion | GCVE Database | 01/26/2026, 19:58:10 UTC Added: 05/26/2026, 20:58:18 UTC |
Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901 Join the discussion | CVE Database V5 | 06/16/2025, 14:50:40 UTC Added: 06/16/2025, 15:04:29 UTC |
Showing 1 to 3 of 3 results