RHSA-2026:34160
Advisory lineage Upstream: 10 Downstream: 0
Published: 02 Jul 2026, 10:17
Last modified:20 Jul 2026, 10:12
Vulnerability Summary
Overall Risk (default)
medium
32/100 CVSS Score
8.1 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
02 Jul 2026, 10:17
Published
Vulnerability first disclosed
20 Jul 2026, 10:12
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected Systems
- redhat•automation-controller
< 0:4.7.13-2.el9ap
- redhat•automation-controller-cli
< 0:4.7.13-2.el9ap
- redhat•automation-controller-server
< 0:4.7.13-2.el9ap
- redhat•automation-controller-ui
< 0:4.7.13-2.el9ap
- redhat•automation-controller-venv-tower
< 0:4.7.13-2.el9ap
- redhat•automation-platform-ui
< 0:2.6.10-1.el9ap
- redhat•python3.12-pyjwt
< 0:2.13.0-1.el9ap
- redhat•python3.12-pyjwt+crypto
< 0:2.13.0-1.el9ap
- redhat•python3.12-urllib3
< 0:2.7.0-1.el9ap
References (60)
- https://access.redhat.com/errata/RHSA-2026:34160
- https://access.redhat.com/security/updates/classification/#important
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade
- https://bugzilla.redhat.com/show_bug.cgi?id=2449774
- https://bugzilla.redhat.com/show_bug.cgi?id=2461147
- https://bugzilla.redhat.com/show_bug.cgi?id=2461606
- https://bugzilla.redhat.com/show_bug.cgi?id=2466684
- https://bugzilla.redhat.com/show_bug.cgi?id=2477104
- https://bugzilla.redhat.com/show_bug.cgi?id=2477154
- https://bugzilla.redhat.com/show_bug.cgi?id=2477167
- https://bugzilla.redhat.com/show_bug.cgi?id=2482734
- https://bugzilla.redhat.com/show_bug.cgi?id=2487937
- https://bugzilla.redhat.com/show_bug.cgi?id=2487949
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_34160.json
- https://access.redhat.com/security/cve/CVE-2026-6322
- https://www.cve.org/CVERecord?id=CVE-2026-6322
- https://nvd.nist.gov/vuln/detail/CVE-2026-6322
- https://cna.openjsf.org/security-advisories.html
- https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc
- https://access.redhat.com/security/cve/CVE-2026-33154
- https://www.cve.org/CVERecord?id=CVE-2026-33154
- https://nvd.nist.gov/vuln/detail/CVE-2026-33154
- https://github.com/dynaconf/dynaconf/commit/2fbb45ee36b8c0caa5b924fe19f3c1a5e8603fa7
- https://github.com/dynaconf/dynaconf/releases/tag/3.2.13
- https://github.com/dynaconf/dynaconf/security/advisories/GHSA-pxrr-hq57-q35p
- https://access.redhat.com/security/cve/CVE-2026-41240
- https://www.cve.org/CVERecord?id=CVE-2026-41240
- https://nvd.nist.gov/vuln/detail/CVE-2026-41240
- https://github.com/cure53/DOMPurify/commit/c361baa18dbdcb3344a41110f4c48ad85bf48f80
- https://github.com/cure53/DOMPurify/releases/tag/3.4.0
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-h7mw-gpvr-xq4m
- https://access.redhat.com/security/cve/CVE-2026-42035
- https://www.cve.org/CVERecord?id=CVE-2026-42035
- https://nvd.nist.gov/vuln/detail/CVE-2026-42035
- https://github.com/axios/axios/security/advisories/GHSA-6chq-wfr3-2hj9
- https://access.redhat.com/security/cve/CVE-2026-44293
- https://www.cve.org/CVERecord?id=CVE-2026-44293
- https://nvd.nist.gov/vuln/detail/CVE-2026-44293
- https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-66ff-xgx4-vchm
- https://access.redhat.com/security/cve/CVE-2026-44431
- https://www.cve.org/CVERecord?id=CVE-2026-44431
- https://nvd.nist.gov/vuln/detail/CVE-2026-44431
- https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc
- https://access.redhat.com/security/cve/CVE-2026-44432
- https://www.cve.org/CVERecord?id=CVE-2026-44432
- https://nvd.nist.gov/vuln/detail/CVE-2026-44432
- https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j
- https://access.redhat.com/security/cve/CVE-2026-44488
- https://www.cve.org/CVERecord?id=CVE-2026-44488
- https://nvd.nist.gov/vuln/detail/CVE-2026-44488
- https://github.com/axios/axios/security/advisories/GHSA-777c-7fjr-54vf
- https://access.redhat.com/security/cve/CVE-2026-44495
- https://www.cve.org/CVERecord?id=CVE-2026-44495
- https://nvd.nist.gov/vuln/detail/CVE-2026-44495
- https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw
- https://access.redhat.com/security/cve/CVE-2026-48526
- https://www.cve.org/CVERecord?id=CVE-2026-48526
- https://nvd.nist.gov/vuln/detail/CVE-2026-48526
- https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx