RHSA-2026:1596HighCVSS 8.3
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update
🔗 CVE IDs covered (8)
📋 Description
CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-62706 — authlib: Authlib : JWE zip=DEF decompression bomb enables DoS CVE-2025-64459 — django: Django SQL injection CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion CVE-2025-66416 — mcp: DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2025-69223 — aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:1596
- externalhttps://access.redhat.com/security/cve/CVE-2025-15284
- externalhttps://access.redhat.com/security/cve/CVE-2025-62706
- externalhttps://access.redhat.com/security/cve/CVE-2025-64459
- externalhttps://access.redhat.com/security/cve/CVE-2025-66031
- externalhttps://access.redhat.com/security/cve/CVE-2025-66416
- externalhttps://access.redhat.com/security/cve/CVE-2025-66471
- externalhttps://access.redhat.com/security/cve/CVE-2025-69223
- externalhttps://access.redhat.com/security/cve/CVE-2026-21441
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/html/release_notes/patch_releases#aap-26-20260121
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_1596.json