RHSA-2026:24762
Advisory lineage Upstream: 12 Downstream: 0
Published: 10 Jun 2026, 10:08
Last modified:19 Sept 2026, 10:08
Vulnerability Summary
Overall Risk (default)
medium
32/100 CVSS Score
8.1 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
10 Jun 2026, 10:08
Published
Vulnerability first disclosed
19 Sept 2026, 10:08
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•automation-controller
< 0:4.7.12-1.el9ap
- redhat•automation-controller-cli
< 0:4.7.12-1.el9ap
- redhat•automation-controller-server
< 0:4.7.12-1.el9ap
- redhat•automation-controller-ui
< 0:4.7.12-1.el9ap
- redhat•automation-controller-venv-tower
< 0:4.7.12-1.el9ap
- redhat•automation-gateway-proxy
< 0:2.6.14-3.el9ap
- redhat•automation-gateway-proxy-debugsource
< 0:2.6.14-3.el9ap
- redhat•automation-gateway-proxy-server
< 0:2.6.14-3.el9ap
- redhat•automation-gateway-proxy-server-debuginfo
< 0:2.6.14-3.el9ap
- redhat•automation-platform-ui
< 0:2.6.9-1.el9ap
- redhat•python3-click
< 0:8.3.3-1.el10ap
- redhat•python3.12-click
< 0:8.3.3-1.el9ap
- redhat•python3.12-cryptography
< 0:46.0.7-1.el9ap
- redhat•python3.12-cryptography-debuginfo
< 0:46.0.7-1.el9ap
- redhat•python3.12-cryptography-debugsource
< 0:46.0.7-1.el9ap
- redhat•python3.12-pillow
< 0:12.2.0-1.el9ap
- redhat•python3.12-pillow-debuginfo
< 0:12.2.0-1.el9ap
- redhat•python3.12-pillow-debugsource
< 0:12.2.0-1.el9ap
- redhat•receptor
< 0:1.6.5-1.el10ap | < 0:1.6.5-1.el9ap
- redhat•receptor-debuginfo
< 0:1.6.5-1.el10ap | < 0:1.6.5-1.el9ap
- redhat•receptor-debugsource
< 0:1.6.5-1.el10ap | < 0:1.6.5-1.el9ap
- redhat•receptorctl
< 0:1.6.5-1.el10ap | < 0:1.6.5-1.el9ap
References (84)
- https://access.redhat.com/errata/RHSA-2026:24762
- https://access.redhat.com/security/updates/classification/#important
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade
- https://bugzilla.redhat.com/show_bug.cgi?id=2448553
- https://bugzilla.redhat.com/show_bug.cgi?id=2451867
- https://bugzilla.redhat.com/show_bug.cgi?id=2452450
- https://bugzilla.redhat.com/show_bug.cgi?id=2453496
- https://bugzilla.redhat.com/show_bug.cgi?id=2456179
- https://bugzilla.redhat.com/show_bug.cgi?id=2456336
- https://bugzilla.redhat.com/show_bug.cgi?id=2456338
- https://bugzilla.redhat.com/show_bug.cgi?id=2456339
- https://bugzilla.redhat.com/show_bug.cgi?id=2456735
- https://bugzilla.redhat.com/show_bug.cgi?id=2457432
- https://bugzilla.redhat.com/show_bug.cgi?id=2458856
- https://bugzilla.redhat.com/show_bug.cgi?id=2464121
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_24762.json
- https://access.redhat.com/security/cve/CVE-2026-4800
- https://www.cve.org/CVERecord?id=CVE-2026-4800
- https://nvd.nist.gov/vuln/detail/CVE-2026-4800
- https://cna.openjsf.org/security-advisories.html
- https://github.com/advisories/GHSA-35jh-r3h4-6jhm
- https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c
- https://access.redhat.com/security/cve/CVE-2026-4926
- https://www.cve.org/CVERecord?id=CVE-2026-4926
- https://nvd.nist.gov/vuln/detail/CVE-2026-4926
- https://access.redhat.com/security/cve/CVE-2026-7246
- https://www.cve.org/CVERecord?id=CVE-2026-7246
- https://nvd.nist.gov/vuln/detail/CVE-2026-7246
- https://github.com/pallets/click/releases/tag/8.3.3
- https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
- https://access.redhat.com/security/cve/CVE-2026-30922
- https://www.cve.org/CVERecord?id=CVE-2026-30922
- https://nvd.nist.gov/vuln/detail/CVE-2026-30922
- https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r
- https://access.redhat.com/security/cve/CVE-2026-32280
- https://www.cve.org/CVERecord?id=CVE-2026-32280
- https://nvd.nist.gov/vuln/detail/CVE-2026-32280
- https://go.dev/cl/758320
- https://go.dev/issue/78282
- https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU
- https://pkg.go.dev/vuln/GO-2026-4947
- https://access.redhat.com/security/cve/CVE-2026-32282
- https://www.cve.org/CVERecord?id=CVE-2026-32282
- https://nvd.nist.gov/vuln/detail/CVE-2026-32282
- https://go.dev/cl/763761
- https://go.dev/issue/78293
- https://pkg.go.dev/vuln/GO-2026-4864
- https://access.redhat.com/security/cve/CVE-2026-32283
- https://www.cve.org/CVERecord?id=CVE-2026-32283
- https://nvd.nist.gov/vuln/detail/CVE-2026-32283
- https://go.dev/cl/763767
- https://go.dev/issue/78334
- https://pkg.go.dev/vuln/GO-2026-4870
- https://access.redhat.com/security/cve/CVE-2026-33891
- https://www.cve.org/CVERecord?id=CVE-2026-33891
- https://nvd.nist.gov/vuln/detail/CVE-2026-33891
- https://github.com/digitalbazaar/forge/commit/9bb8d67b99d17e4ebb5fd7596cd699e11f25d023
- https://github.com/digitalbazaar/forge/security/advisories/GHSA-5m6q-g25r-mvwx
- https://access.redhat.com/security/cve/CVE-2026-39363
- https://www.cve.org/CVERecord?id=CVE-2026-39363
- https://nvd.nist.gov/vuln/detail/CVE-2026-39363
- https://github.com/vitejs/vite/security/advisories/GHSA-p9ff-h696-f583
- https://access.redhat.com/security/cve/CVE-2026-39892
- https://www.cve.org/CVERecord?id=CVE-2026-39892
- https://nvd.nist.gov/vuln/detail/CVE-2026-39892
- http://www.openwall.com/lists/oss-security/2026/04/08/12
- https://github.com/pyca/cryptography/commit/622d672e429a7cff836a23c5903683dbec1901f5
- https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq
- https://access.redhat.com/security/cve/CVE-2026-40175
- https://www.cve.org/CVERecord?id=CVE-2026-40175
- https://nvd.nist.gov/vuln/detail/CVE-2026-40175
- https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1
- https://github.com/axios/axios/pull/10660
- https://github.com/axios/axios/releases/tag/v1.15.0
- https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx
- https://access.redhat.com/security/cve/CVE-2026-40192
- https://www.cve.org/CVERecord?id=CVE-2026-40192
- https://nvd.nist.gov/vuln/detail/CVE-2026-40192
- https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628
- https://github.com/python-pillow/Pillow/pull/9521
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j
- https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb