Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
🔗 CVE IDs covered (21)
📋 Description
CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-6321 — fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite CVE-2026-11332 — ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution CVE-2026-12382 — aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing CVE-2026-12701 — pulpcore: pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2026:42078
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453496
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456333
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2460927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461624
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2466582
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2466684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487938
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487942
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487943
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487947
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487948
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489126
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2490703
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42078.json