RHSA-2025:23069HighCVSS 8.3

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update

Published
December 10, 2025
Last Modified
July 8, 2026

🔗 CVE IDs covered (6)

CVE-2025-9907 · pendingCVE-2025-9908 · pendingCVE-2025-9909 · pendingCVE-2025-58754CVE-2025-59530CVE-2025-64459

📋 Description

CVE-2025-9907 — event-driven-ansible: Event Stream Test Mode Exposes Sensitive Headers in AAP EDA CVE-2025-9908 — event-driven-ansible: Sensitive Internal Headers Disclosure in AAP EDA Event Streams CVE-2025-9909 — aap-gateway: Improper Path Validation in Gateway Allows Credential Exfiltration CVE-2025-58754 — axios: Axios DoS via lack of data size check CVE-2025-59530 — github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame CVE-2025-64459 — django: Django SQL injection

🔗 References (9)