Red Hat Ansible Automation Platform
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Red Hat Ansible Automation Platform.
Recent Red Hat Ansible Automation Platform Security Advisories
| Advisory | Title | Published |
|---|---|---|
| RHSA-2026:73135 | (RHSA-2026:73135) Red Hat Ansible Automation Platform Execution Environments Update | September 29, 2026 |
| RHSA-2026:73134 | (RHSA-2026:73134) Red Hat Ansible Automation Platform Execution Environments Update | September 29, 2026 |
| RHSA-2026:73133 | (RHSA-2026:73133) Red Hat Ansible Automation Platform Execution Environments Update | September 29, 2026 |
| RHSA-2026:73132 | (RHSA-2026:73132) Red Hat Ansible Automation Platform Execution Environments Update | September 29, 2026 |
| RHSA-2026:71210 | (RHSA-2026:71210) Red Hat Ansible Automation Platform 2.5 Container Release Update | September 23, 2026 |
| RHSA-2026:71192 | (RHSA-2026:71192) Red Hat Ansible Automation Platform 2.5 Container Release Update | September 23, 2026 |
| RHSA-2026:71179 | (RHSA-2026:71179) Red Hat Ansible Automation Platform 2.6 Container Release Update | September 23, 2026 |
| RHSA-2026:71177 | (RHSA-2026:71177) Red Hat Ansible Automation Platform 2.7 Container Release Update | September 23, 2026 |
| RHSA-2026:71115 | (RHSA-2026:71115) Critical: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update | September 23, 2026 |
| RHSA-2026:71114 | (RHSA-2026:71114) Critical: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update | September 23, 2026 |
By the Year
In 2026 there have been 203 vulnerabilities in Red Hat Ansible Automation Platform with an average score of 7.4 out of ten. Last year, in 2025 Ansible Automation Platform had 11 security vulnerabilities published. That is, 192 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.13.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 203 | 7.44 |
| 2025 | 11 | 6.31 |
| 2024 | 16 | 6.25 |
| 2023 | 7 | 6.87 |
| 2022 | 5 | 6.02 |
| 2021 | 4 | 7.10 |
It may take a day or so for new Ansible Automation Platform vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Ansible Automation Platform Security Vulnerabilities
Red Hat Pulp Core Path Traversal via file_url in Content Upload API
CVE-2026-90959
8.1 - High
- September 24, 2026
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double slashes, creating a mismatch between what is validated and what is dispatched to the file downloader. An authenticated user with low-privilege repository permissions can supply a specially crafted URL using relative path traversal sequences to read any file accessible to the Pulp server process. In deployments that include Pulp Container, successful exploitation allows an attacker to read the container registry token signing private key and forge bearer tokens, granting unauthorized access to all private container repositories in the affected registry.
Directory traversal
Authorization Bypass in Red Hat Ansible Automation Platform Gateway
CVE-2026-94416
6.8 - Medium
- September 24, 2026
An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an administrator-issued key is cryptographically indistinguishable from a legitimate one and can be used to forge a service-authentication token that impersonates the Controller service. Combined with the gateway OIDC workload-identity endpoint (enabled via FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED), the attacker can drive the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. A downstream resource server such as HashiCorp Vault that trusts the gateway OIDC key will accept the forged WIT and return the AAP credentials bound to that workload, disclosing secrets beyond the attacker's authorization boundary.
Authentication Bypass by Spoofing
Arg Injection in Ansible Automation Platform Automation Controller System-Job
CVE-2026-84724
6.6 - Medium
- September 23, 2026
An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command argument list into a single string with spaces before the job runner re-splits it, so spaces in the value become additional command-line arguments. Because system jobs are executed in-process on the control node without the container isolation applied to all other job types, an authenticated user with superuser privileges can inject arbitrary arguments including Python's path option into the control-plane awx-manage process, controlling its argument vector and the first entry of its module search path. Full remote code execution requires an additional import gadget that is not present in the current management commands, so the demonstrated impact is argument injection with control of the process search path rather than confirmed code execution.
Argument Injection
SSRF in Ansible Automation Platform Email Backend Enables Internal Port Scan
CVE-2026-84721
6.4 - Medium
- September 23, 2026
A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the SMTP client without validating that the target is not an internal, loopback, link-local, or reserved address. An authenticated user with organization notification-admin permission can create or modify an email notification template pointing at an arbitrary internal address, trigger a test, and have the controller task process open a raw TCP connection to that address. The resulting connection error is reflected back through the notification record, providing a three-state internal port-scan oracle (open, closed, filtered) over the control-plane's cluster network, including the in-cluster Kubernetes API. When a shared organization template holds a stored SMTP password, redirecting the host can also cause that credential to be transmitted to an attacker-controlled server.
SSRF
Ansible Automation Platform: WorkflowJobNode DB Leak via Unfiltered ancestor_artifacts
CVE-2026-84720
6.5 - Medium
- September 23, 2026
A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent_search() and is therefore accepted for arbitrary field lookups by the REST filter backend, even though it is omitted from the API serializer. Because the column is persisted before Ansible's no_log masking is applied, a user with only read access to a workflow or, via a regular-expression lookup that bypasses the JSON cross-relation filter guard through the world-readable credential-types endpoint, any authenticated user with no roles can use the result count as a boolean/count oracle to recover, character by character, secret values that a playbook author explicitly marked no_log, including across organizations.
Insecure Direct Object Reference / IDOR
Ansible Automation Platform: X-Forwarded-For Header Trust (CVE-2026-84718)
CVE-2026-84718
4.3 - Medium
- September 23, 2026
A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled) header value. As a result, an attacker can forge the source IP address recorded for their requests in the Controller's audit and access logs, degrading the integrity of forensic and SIEM attribution. The flaw does not grant additional access.
Use of Less Trusted Source
Ansible Platform: Unauth Bitbucket DC Webhook HMAC Bypass ID Enumeration
CVE-2026-84717
5.3 - Medium
- September 23, 2026
A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key.
Observable Response Discrepancy
Red Hat Automation Controller: TLS Impersonation via Case-Insensitive Hostname
CVE-2026-84716
6.6 - Medium
- September 23, 2026
A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 certificate with the receptor mesh certificate authority in which the Common Name, DNS subject-alternative-name, and receptor node-id are taken verbatim from the caller-chosen instance hostname, with a hard-coded ten-year validity, a random serial, and no issuance log or revocation list. Because the hostname charset validator is case-insensitive while the uniqueness validator is case-sensitive, an administrator can register a case variant of an existing control node's hostname and obtain a mesh-CA-signed certificate that TLS peers, which match hostnames case-insensitively, accept as that control node. In managed/hosted deployments where the customer holds controller superuser but the platform operator runs the mesh this yields a long-lived, non-revocable mesh peer credential and, with an on-path position, TLS impersonation or interception of control/hybrid mesh nodes. It does not grant direct remote code execution, because receptor work submission is gated by a separate signing key not included in the bundle.
Incorrect Privilege Assignment
Red Hat Automation Controller: Cleartext Recipient Secret Leak via Notification
CVE-2026-84713
6.5 - Medium
- September 23, 2026
A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is copied in clear text into the unprotected Notification.recipients field on every send. Because the credential-types endpoint is listable by any authenticated user and the API filter backend traverses object relations without per-hop authorization, a user with no privileges can use a relational filter as a boolean count-oracle to recover, character by character and across organizations, the secret recipient values of other tenants' notifications including PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook bearer-token URLs. This flaw affects confidentiality.
Insecure Direct Object Reference / IDOR
Red Hat Automation Controller: /api/v2/ping over-serializes inventory
CVE-2026-84712
5.3 - Medium
- September 23, 2026
A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous response, exposing the full instance inventory (node hostnames, node types, UUIDs, heartbeats, capacities, and exact versions), all instance-group names and membership, the deployment install UUID, and the active control node. A remote, unauthenticated attacker can use this to map the control plane and fingerprint software versions for targeted attacks. This flaw affects confidentiality only; it does not expose secrets, credentials, or tenant data.
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Ansible Platform rsyslog RainerScript Injection Remote Code Execution
CVE-2026-85475
7.2 - High
- September 23, 2026
A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE into an rsyslog RainerScript config file without neutralizing RainerScript syntax. A privileged (superuser) user can inject rsyslog directives, including an omprog action, causing arbitrary command execution inside the control-plane rsyslog component. This allows disclosure of the controller SECRET_KEY and database credentials, decryption of all stored credentials, and full compromise of the control plane.
Static Code Injection
Ansible: Workflow Copy Bypass InstanceGroup Auth (CVE-2026-84719)
CVE-2026-84719
9.9 - Critical
- September 23, 2026
A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use including the control-plane instance group bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context.
AuthZ
Ansible Automation Platform Jinja Injection via sanitize_jinja()
CVE-2026-84714
7.1 - High
- September 23, 2026
A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first interior '}' or '%' character, so a Jinja expression containing an inner brace (for example an empty dict) is accepted while remaining valid Jinja. Because sanitize_jinja() is the sole guard on several launch-time fields ad-hoc command module_args, Machine-credential username / become_method / become_user, and inventory host names a low-privileged user can inject Jinja that ansible-core evaluates in the execution environment. This enables execution of arbitrary commands in the execution environment (bypassing an administrator's AD_HOC_COMMANDS module allowlist) and disclosure of secrets belonging to credentials the attacker cannot read (by templating a co-attached credential's injected environment variables), across the credential access-control boundary.
Denylist / Deny List
Ansible Automation Platform Credential Variable Injection Container RCE
CVE-2026-84706
7.6 - High
- September 23, 2026
A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, PYTHONSTARTUP and GIT_SSH_COMMAND. Combined with the credential file injector, a privileged user can write an attacker-controlled script into the execution environment and point BASH_ENV at it, obtaining arbitrary code execution inside the execution-environment container for any job that attaches a credential of that type.
Denylist / Deny List
AWX Pod Spec Override Priv Esc via InitContainer Injection
CVE-2026-75884
9.1 - Critical
- September 23, 2026
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.
Denylist / Deny List
CVE-2026-84691: Ansible Automation Platform fmt-string leak exposes secrets
CVE-2026-84691
8.7 - High
- September 23, 2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute and item traversal on its arguments, an administrator can craft a template that walks from the user object into the application settings and reads the Django secret key and the database password. The formatted message is written to a logger that can be forwarded to an external log aggregator, whose destination is also administrator-controlled, allowing the secrets to be sent off the host. An authenticated administrator can thereby obtain the master encryption key used to protect all stored credentials and the database service password, enabling offline decryption of every stored credential, forgery of user sessions, and direct access to the controller database.
Use of Externally-Controlled Format String
Red Hat Ansible Automation Platform XSS via Unescaped ANSI Hyperlinks
CVE-2026-84683
8.7 - High
- September 23, 2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the output is expanded into an HTML anchor whose href is not scheme- filtered or escaped, so a low-privileged user who can produce output -- or an external party whose data a playbook echoes -- can embed a javascript: link that is rendered into a text/html response with no Content-Security-Policy. When a higher-privileged user views the output page and clicks the link, attacker- controlled JavaScript executes in their authenticated session, allowing actions as that user up to full platform takeover.
XSS
Red Hat Ansible Automation Platform: Password Disclosure via Survey Revalidation
CVE-2026-84499
7.7 - High
- September 23, 2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller decrypts the stored password and includes its plaintext value in the minimum/maximum length validation error message returned in the HTTP response. A user with the delegated JobTemplate Admin role can tighten the survey length constraint and trigger revalidation of a schedule or node created by another, higher-privileged user, thereby recovering that user's stored password in plaintext.
Generation of Error Message Containing Sensitive Information
CVE-2026-84502: Ansible Automation Platform RCE via Unvalidated scm_url
CVE-2026-84502
9.9 - Critical
- September 23, 2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--" separator, a git project URL such as "--upload-pack=<command>:x" is interpreted by git as the --upload-pack option and executed via a shell. A user with permission to create or modify a project in a single organization can thereby execute arbitrary commands on the control-plane task pod, with output reflected through the project update stdout endpoint, leading to cross-tenant compromise and in-cluster lateral movement
Argument Injection
Red Hat AAP Automation-Controller CVE-2026-84474: Provisioning secret exposed via X-Forwarded-For, R
CVE-2026-84474
9.9 - Critical
- September 23, 2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback endpoint trusts a client-supplied X-Forwarded-For header to determine the calling host when the controller is deployed behind the AAP gateway with an empty proxy allow-list. By reading the secret and spoofing X-Forwarded-For to match any host in the job template's inventory, a minimally privileged or unauthenticated remote attacker can launch the job template against arbitrary managed hosts using the job template's credentials, resulting in privilege escalation and remote code execution on managed hosts.
Reliance on Untrusted Inputs in a Security Decision
Red Hat Ansible: Unauth Debug Endpoints Grant Scheduler Lock Abuse
CVE-2026-84486
8.2 - High
- September 23, 2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and are routed in production builds because their URL include is not gated on the debug setting. An unauthenticated remote attacker can repeatedly invoke these endpoints to acquire the cluster-wide scheduler advisory lock; because the legitimate scheduler acquires the same lock without waiting, the attacker causes real scheduler runs to be skipped, stalling job dispatch for all tenants, while also consuming controller web workers. The debug root view additionally discloses the list of debug endpoints to unauthenticated callers.
Active Debug Code
Ansible-Core RunAdHocCommand Improper Arg Handling Enables CLI Opt Injection
CVE-2026-71465
3.1 - Low
- September 23, 2026
RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob. A limit beginning with - is parsed as an ansible CLI option. Currently limited to short-circuit flags (--version, --help) since injected element displaces required pattern positional. Would escalate if ansible-core ever defaults pattern.
Argument Injection
Ansible Tower RCE via missing leading-dash check in LaunchConfigBaseSerializer
CVE-2026-71464
3.1 - Low
- September 23, 2026
LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers. Schedule and WFJT Node accept --upload-pack=/bin/id as scm_branch. Currently blocked at runtime by jobs.py:1502 ValueError check (defense-in-depth), but the API validation gap means sole reliance on a task-layer guard. Refactoring that guard away would promote this to RCE.
Argument Injection
Ansible Tower Jinja AST whitelist bypass leaks tracebacks via webhook
CVE-2026-71463
2.7 - Low
- September 23, 2026
Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id > 100 %} conditional gating bypass both the AST check and the test-render (stub has small job.id). At runtime, the gated branch executes and exceptions write full tracebacks into notification body, which is POSTed to attacker-controlled webhook URL. Leaks install paths, Python version, source line numbers.
Generation of Error Message Containing Sensitive Information
AAP Path Disclosure via StringListPathField
CVE-2026-71462
4.1 - Medium
- September 23, 2026
StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenant superuser can confirm /etc/tower/SECRET_KEY, k8s service-account token, receptor sockets, ConfigMap mount points. Mainly impactful on managed AAP (ansiblecloud.com) where tenant admin != host admin.
Observable Response Discrepancy
Red Hat Satellite HostList Leak: ORM Schema & DB Errors via Django
CVE-2026-71461
4.3 - Medium
- September 23, 2026
HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) or PostgreSQL DataError (leaking raw database error strings). Two primitives: credential__search=x dumps ORM schema, name__regex=[bad reflects PostgreSQL errors.
Generation of Error Message Containing Sensitive Information
Red Hat SubscriptionAPI: License Info leaked to any Authenticated User
CVE-2026-71460
4.3 - Medium
- September 23, 2026
/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuser/auditor gate only covers project_base_dir/project_local_paths/custom_virtualenvs, not license_info. Enables social engineering against Red Hat support and estate sizing reconnaissance.
AuthZ
AWX CopyAPIView POST bypasses RBAC, enabling unauthorized template copy
CVE-2026-76648
8.5 - High
- September 23, 2026
CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) but post() (lines 10011010) does not. POST only checks: can_access(model, 'add', create_kwargs_check) can_access(model, 'copy_related', obj) For JobTemplate, can_add (awx/awx/main/access.py:14651520) gates on inventory.use_role + project.use_role + execution_environment.read_role resource-level roles that do not imply read on the source JT and can_copy_related (15221534) checks only credentials.use_role. None of these imply the caller can read the source JT.
AuthZ
Red Hat Job Scheduler DRF Permission Bypass in Child Events
CVE-2026-71459
5 - Medium
- September 23, 2026
JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user. The view uses raw get_object_or_404(Job, pk) without DRF object-level permission check. Zero-privilege user reads event tree structure, event_processing_finished status, and enumerates Job IDs platform-wide via 200/404 oracle. Sibling endpoint /jobs/{id}/job_events/ correctly returns 403.
AuthZ
Ansible Tower URLModificationMiddleware Cross-Tenant Hostname Enumeration
CVE-2026-71458
5 - Medium
- September 23, 2026
URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 detail string. Differential "Not found." vs "No <Model> matches..." reveals whether a named resource (org, credential, inventory, host) exists anywhere on the platform. Enables cross-tenant internal hostname enumeration.
Observable Response Discrepancy
Redis Community Cluster Bus OOB Read via Unchecked Null-Termination
CVE-2026-92925
7.1 - High
- September 17, 2026
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
Out-of-bounds Read
A flaw was found in sequoia-openpgp
CVE-2026-42784
7.4 - High
- September 16, 2026
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.
Improper Verification of Cryptographic Signature
A flaw was found in jwcrypto
CVE-2026-92091
5.9 - Medium
- September 16, 2026
A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacker can supply a JWK with a large key_ops array to an application that passes attacker-controlled key material to a public key-import API (reachable via ECDH-ES key agreement, OIDC dynamic client registration, DPoP, or ACME account key registration, among others) to consume excessive CPU time, resulting in a denial of service.
Inefficient Algorithmic Complexity
A flaw was found in the containers/storage library
CVE-2026-79699
4.4 - Medium
- September 15, 2026
A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer.
insecure temporary file
A flaw was found in the buildah/copier Go package
CVE-2026-79705
4.5 - Medium
- September 15, 2026
A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.
Directory traversal
jwcrypto General JWS Verification Bypass via Key ID Misidentification
CVE-2026-84185
5.9 - Medium
- September 03, 2026
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users.
Improper Verification of Cryptographic Signature
Ansible Automation Platform Bulk Job Launch API Permission Bypass
CVE-2026-84470
6.4 - Medium
- September 01, 2026
A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A principal that holds read (but not use) permission on an instance group -- for example the built-in read-only System Auditor role -- together with execute permission on a job template can launch bulk jobs onto instance groups they are not authorized to use, bypassing execution-placement isolation.
AuthZ
Stored XSS via HTML/SVG in pulpcore content serving
CVE-2026-84232
5.4 - Medium
- September 01, 2026
A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application.
XSS
jwcrypto JWE Deserialization Memory Overrun DoS
CVE-2026-80179
5.9 - Medium
- August 27, 2026
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values.
Allocation of Resources Without Limits or Throttling
SSRF in galaxy_ng Ansible Galaxy plugin via avatar URL
CVE-2026-79717
6.4 - Medium
- August 25, 2026
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or cloud instance metadata endpoints. A background worker fetches that URL without checking the destination, which lets the attacker probe internal services and enumerate reachable IP addresses. The HTTP client is also configured without an overall timeout, so a slow or non-responsive target can pin workers and cause a denial of service.
SSRF
SSRF in Red Hat AWX Notif Backends: Webhook, Mattermost, Rocket.Chat, Grafana
CVE-2026-71366
7.7 - High
- August 24, 2026
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates pointing to internal or loopback addresses, causing the AWX control node to issue HTTP requests to services that are not externally accessible. Additionally, the webhook notification backend follows HTTP redirects and resends configured Basic Authentication credentials to redirect targets regardless of host change, allowing an attacker to exfiltrate notification credentials by redirecting to an attacker-controlled host. The Grafana backend sends its API key in the Authorization header to the configured target URL.
SSRF
AWX Project Archive Path Traversal for Arbitrary File Write
CVE-2026-71364
7.2 - High
- August 24, 2026
A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the member filename without performing path normalization, boundary validation, or rejecting directory traversal sequences. A malicious archive containing members with path traversal components can write files to arbitrary locations on the execution node's filesystem outside the intended project directory. An attacker who controls the archive content, either through a compromised upstream source, a malicious archive URL, or a man-in-the-middle attack on a plain HTTP connection, can achieve arbitrary file writes as the user performing the extraction, potentially leading to remote code execution through mechanisms such as cron files, SSH authorized keys, or playbook content injection.
Directory traversal
AWX SSRF via webhook status callback leaks Git PAT to attacker
CVE-2026-71365
7.7 - High
- August 18, 2026
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload without validating the target host against the expected Git provider. This URL is persisted in job extra variables and later used to send authenticated status updates. A user with admin role on a webhook-enabled job template can read the template's webhook signing key, forge a signed GitHub webhook payload with an arbitrary statuses_url, and cause AWX to POST status updates to an attacker-controlled or internal URL. The status update request includes the configured Git Personal Access Token (PAT) in the Authorization header, resulting in credential leakage to the attacker-specified endpoint.
SSRF
AAP Controller HashiCorp Vault Plugin Exfil Insecure Token Leak
CVE-2026-12564
9.6 - Critical
- August 18, 2026
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY.
SSRF
Podman 5.8.x Quadlet Replace Truncation Flaw Security Data Leakage
CVE-2026-19730
4.2 - Medium
- August 13, 2026
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in ReflinkOrCopy uses io.Copy which performs a non-truncating write. If the original Quadlet is larger than the new Quadlet, the file is not truncated and content from the original is preserved. The command completes with no warning. There is no risk of information leakage as the user already had access to the Quadlet in order to replace it, and in most cases, this would only lead to invalid Quadlet files. However, security-related options from the end of the old Quadlet could be included in the new Quadlet, and if the truncation resulted in a valid Quadlet file, this could result in undesirable behavior. For example, running podman quadlet install --replace to remove a single line from the end of a Quadlet - including security-sensitive content, like AddCapability - will fail, and the option will continue to be used. Further, with Volume Quadlets, this can include additional mounts which can cause content to be unintentionally exposed into containers. If, later, the image is updated then compromised content might be leaked to an attacker. The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go (lines 338-360, O_CREATE|O_WRONLY without O_TRUNC) and vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines 12-19, non-truncating io.Copy fallback).
Insufficient Cleanup
Unauthenticated mTLS Bypass & Event Injection in Ansible EDA aap-gateway
CVE-2026-18141
8.2 - High
- July 31, 2026
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.
Improper Certificate Validation
EDA Server Permissive Access Allows Event Injection via Spoofed Header
CVE-2026-12383
7.5 - High
- July 27, 2026
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentication without verifying that the header originated from a trusted proxy. Additionally, the expected certificate Distinguished Name is leaked in the 403 error response body. An attacker who can reach the EDA API endpoint with a spoofed Subject header can inject arbitrary events into mTLS-protected event streams, triggering downstream automation actions.
Insufficient Verification of Data Authenticity
CVE-2026-44191 VSCode Ansible Lightspeed Cmd Injection RCE
CVE-2026-44191
7.8 - High
- July 22, 2026
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing a playbook. Successful exploitation leads to remote code execution (RCE) on the victim's machine with the privileges of the Visual Studio Code user, potentially resulting in a complete system compromise.
Shell injection
Ansible Lightspeed VSCode Ext Exposes Google Gemini API Key
CVE-2026-44187
3.3 - Low
- July 22, 2026
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's configuration file and writes it to output log files. This information disclosure can lead to the attacker obtaining the API credential and potentially consuming the user's API quota.
Unprotected Storage of Credentials
Path Traversal in Ansible Lightspeed MCP Server Allows Prompt Injection
CVE-2026-44192
6.6 - Medium
- July 22, 2026
A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the server to write files to unauthorized locations on the user's system. This can result in the exposure of sensitive host information and enable the attacker to execute malicious commands, potentially leading to a full system compromise.
Directory traversal
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Red Hat Ansible Automation Platform or by Red Hat? Click the Watch button to subscribe.