Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update
🔗 CVE IDs covered (14)
📋 Description
CVE-2025-62718 — axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization CVE-2026-4926 — path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions CVE-2026-6321 — fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVE-2026-28390 — openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing CVE-2026-28684 — python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following CVE-2026-33154 — dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection CVE-2026-39363 — Vite: Vite: Information disclosure via WebSocket connection bypasses access control CVE-2026-39364 — vite: Vite: Information disclosure via query parameter manipulation on the development server CVE-2026-39892 — cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API CVE-2026-40192 — Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing CVE-2026-40217 — LiteLLM: LiteLLM: Arbitrary Code Execution via bytecode rewriting CVE-2026-41140 — poetry: Poetry: Path traversal vulnerability allows arbitrary file write via malicious package extraction CVE-2026-48710 — starlette: Starlette: Security restriction bypass via malformed HTTP Host header
🎯 Affected products115
- Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:3362761d6a5d99330d303adc87e1181369243147d56347362bfba62cc8047081_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:862cb4601db2eb288b72e993ed1c4b6bbb2e4dd37050d549ba86e6eafc3f1045_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:906f8d05d464820d7f46e9e3e437700adb70397eab300f2c0a2f281ee5322dfd_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/aap-must-gather-rhel9@sha256:a9ec99ae45084783f79da5a8e41f42763b006489c84ffae0758ce12cea05948d_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:9e37aeb2f8f5d89367c4c1415abbd66464aae126eda811f832a87c7fa1e914b0_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:a35e350ec5c0172601f25ac89fcbc48ff8c83ad2c5fdf798de917d9b046c9cc7_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:d833ed5b6de160d7e0cbf35cd5d7f93bfaa74acb2b12846ccc1eef41ef48074d_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-builder-rhel9@sha256:e81951b19451ffa56f4d44225c241229db250e2b87b0cf546d57506ad0911f41_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:443ed5ee0076c027a2af55183ce364225dce498e42fccdb259efd69ff412675f_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:b5424fd9f704ddf4ab272fc1629a64d3a658b9aa40c4dcfac58dd6ca51b48220_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:ccbd0249255d0fc1434a1c6fde96fbd6dc1059becefaa475d9cddd61dff0a970_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/ansible-dev-tools-rhel9@sha256:fb3278021a45367ac357ed32872eb4e671844faad6b9eb9b08db0e476849bae4_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:17ed60234239a1b0b5081ae28b2a2a154ed79eaac34c0cf502c45bef6bb90c0a_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:754ad996d3fb66fffb7bfe0ee9289c9191b3ccecebd509ea99b3906f6f9e2208_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:a11554edb0f50083024b36f2dc13c5b6a60211a1ecaad30a78409a433512a705_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9-operator@sha256:f01ed355b061010f9584a77daad927f1ccca5097cc17e16823fdd2818508578b_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:77ab5de9e627656bd9668724e2f59a37510a4905801edd183ecf380dcd9fe585_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:b37af6bef902e0eb955654296154355ed9941569929d2db7a22a595b0fa0162c_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:c076cf5c0e56918bb49e8c353bc48265a9d88834934563259308cad15eb304e2_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/controller-rhel9@sha256:dfc798d88444141412d07492a1f426f083c6b7e3499db2f78abfeba0123c5821_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:08bef41a15e546deccf883d64ce525df7efd0511a5a52872f1e7486d3a4e0e75_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:1f03bd9054901f83e354a52bde14ad3e5ad8e556db128e22cf7ebe7a46ac7c44_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:76084c25d8de65c919ec760b8ddb9ae338da5cebe4b9ea03294c7b6466e0c3b6_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-minimal-rhel9@sha256:c135bdbb6697bdfd4d711d71f70d915839c08057ba7aab7bf7117643f1f47bf8_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:01780af012f7fad2b3f8975e9a77a8e9d85913ac6869c60d94b9f7b0e71c4e41_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:12726676bf7f888bf49734aab1616046d8c3cef36cda5016de02cb09e36b51a5_s390x as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:6b5eac6cb840fc63462c7ba90f9119425b47abe39ce3a035c58aa1c24d20274e_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/de-supported-rhel9@sha256:72e638615fa4eccc23719eb2cc6892531508c41a2b3b80efcdcd34360d99b6e9_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-26/eda-controller-rhel9-operator@sha256:5cd20de178fd45b1775781a93e4e62bd61023175d5faf624ac8d8713fd7f8fe2_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- +85 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, limit the use of multiple sequential optional groups in route patterns within applications that use `path-to-regexp`. Additionally, avoid directly passing user-controlled input as route patterns to prevent the generation of maliciously crafted regular expressions. Workaround: Applications that process Cryptographic Message Syntax (CMS) EnvelopedData messages should be configured to only accept input from trusted sources. Restricting network access to services that process untrusted CMS data can also reduce exposure to this Denial of Service vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Deploying an RFC-compliant reverse proxy (such as nginx, Apache, HAProxy, or Caddy) in front of the ASGI server will reject malformed Host headers before they reach the application. This is the most straightforward mitigation that does not require code changes. If custom middleware is present, it should be updated to use `request.scope["path"]` instead of `request.url.path` for any security decisions. The ASGI scope path is derived from the HTTP request line and is not influenced by the Host header, so it reflects the actual request target.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2026:24866
- externalhttps://access.redhat.com/security/cve/CVE-2025-62718
- externalhttps://access.redhat.com/security/cve/CVE-2026-23490
- externalhttps://access.redhat.com/security/cve/CVE-2026-28390
- externalhttps://access.redhat.com/security/cve/CVE-2026-28684
- externalhttps://access.redhat.com/security/cve/CVE-2026-33154
- externalhttps://access.redhat.com/security/cve/CVE-2026-39363
- externalhttps://access.redhat.com/security/cve/CVE-2026-39364
- externalhttps://access.redhat.com/security/cve/CVE-2026-39892
- externalhttps://access.redhat.com/security/cve/CVE-2026-40192
- externalhttps://access.redhat.com/security/cve/CVE-2026-40217
- externalhttps://access.redhat.com/security/cve/CVE-2026-41140
- externalhttps://access.redhat.com/security/cve/CVE-2026-48710
- externalhttps://access.redhat.com/security/cve/CVE-2026-4926
- externalhttps://access.redhat.com/security/cve/CVE-2026-6321
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_24866.json