Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
🔗 CVE IDs covered (11)
📋 Description
CVE-2025-14550 — Django: Django: Denial of Service via crafted request with duplicate headers CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-69223 — aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb CVE-2026-0994 — python: protobuf: Protobuf: Denial of Service due to recursion depth bypass CVE-2026-1207 — Django: Django: SQL Injection via RasterField band index parameter CVE-2026-1285 — Django: Django: Denial of Service via crafted HTML inputs CVE-2026-1287 — Django: Django: SQL Injection via crafted column aliases CVE-2026-1312 — Django: Django: SQL injection via crafted column aliases in QuerySet.order_by() CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-23490 — pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:3959
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2427456
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2430472
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2431959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2432398
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2434432
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436338
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436339
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2436342
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3959.json