RHSA-2026:42144HighCVSS 8.0

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Container Release Update

Published
July 20, 2026
Last Modified
July 22, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-57847 — ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions CVE-2026-8643 — python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite CVE-2026-44431 — urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens

🔗 References (9)