RHSA-2026:42078
Advisory lineage Upstream: 24 Downstream: 0
Published: 23 Jul 2026, 10:13
Last modified:19 Sept 2026, 10:10
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9 CRITICAL
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
23 Jul 2026, 10:13
Published
Vulnerability first disclosed
19 Sept 2026, 10:10
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
CVSS Metrics
- v3.1•CRITICAL•Score: 9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
Affected Systems
- redhat•ansible-core
< 1:2.16.19-1.el8ap | < 1:2.16.19-1.el9ap
- redhat•automation-controller-venv-tower
< 0:4.6.30-2.el8ap | < 0:4.6.30-2.el9ap
- redhat•automation-gateway-server
< 0:2.5.20260715-1.el8ap | < 0:2.5.20260715-1.el9ap
- redhat•python3.12-gitpython
< 0:3.1.50-1.el8ap | < 0:3.1.50-1.el9ap
- redhat•python3.12-pulpcore
< 0:3.49.63-2.el8ap | < 0:3.49.63-2.el9ap
- redhat•receptor
< 0:1.6.6-1.el8ap | < 0:1.6.6-1.el9ap
- redhat•receptor-debuginfo
< 0:1.6.6-1.el8ap | < 0:1.6.6-1.el9ap
- redhat•receptor-debugsource
< 0:1.6.6-1.el8ap | < 0:1.6.6-1.el9ap
- redhat•receptorctl
< 0:1.6.6-1.el8ap | < 0:1.6.6-1.el9ap
References (140)
- https://access.redhat.com/errata/RHSA-2026:42078
- https://access.redhat.com/security/updates/classification/#important
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading
- https://bugzilla.redhat.com/show_bug.cgi?id=2453496
- https://bugzilla.redhat.com/show_bug.cgi?id=2456333
- https://bugzilla.redhat.com/show_bug.cgi?id=2460927
- https://bugzilla.redhat.com/show_bug.cgi?id=2461624
- https://bugzilla.redhat.com/show_bug.cgi?id=2466582
- https://bugzilla.redhat.com/show_bug.cgi?id=2466684
- https://bugzilla.redhat.com/show_bug.cgi?id=2467822
- https://bugzilla.redhat.com/show_bug.cgi?id=2477154
- https://bugzilla.redhat.com/show_bug.cgi?id=2480756
- https://bugzilla.redhat.com/show_bug.cgi?id=2480757
- https://bugzilla.redhat.com/show_bug.cgi?id=2480761
- https://bugzilla.redhat.com/show_bug.cgi?id=2485379
- https://bugzilla.redhat.com/show_bug.cgi?id=2487937
- https://bugzilla.redhat.com/show_bug.cgi?id=2487938
- https://bugzilla.redhat.com/show_bug.cgi?id=2487942
- https://bugzilla.redhat.com/show_bug.cgi?id=2487943
- https://bugzilla.redhat.com/show_bug.cgi?id=2487947
- https://bugzilla.redhat.com/show_bug.cgi?id=2487948
- https://bugzilla.redhat.com/show_bug.cgi?id=2487949
- https://bugzilla.redhat.com/show_bug.cgi?id=2489126
- https://bugzilla.redhat.com/show_bug.cgi?id=2490703
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42078.json
- https://access.redhat.com/security/cve/CVE-2026-4800
- https://www.cve.org/CVERecord?id=CVE-2026-4800
- https://nvd.nist.gov/vuln/detail/CVE-2026-4800
- https://cna.openjsf.org/security-advisories.html
- https://github.com/advisories/GHSA-35jh-r3h4-6jhm
- https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c
- https://access.redhat.com/security/cve/CVE-2026-6321
- https://www.cve.org/CVERecord?id=CVE-2026-6321
- https://nvd.nist.gov/vuln/detail/CVE-2026-6321
- https://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6
- https://access.redhat.com/security/cve/CVE-2026-6322
- https://www.cve.org/CVERecord?id=CVE-2026-6322
- https://nvd.nist.gov/vuln/detail/CVE-2026-6322
- https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc
- https://access.redhat.com/security/cve/CVE-2026-8643
- https://www.cve.org/CVERecord?id=CVE-2026-8643
- https://nvd.nist.gov/vuln/detail/CVE-2026-8643
- https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb
- https://access.redhat.com/security/cve/CVE-2026-11332
- https://www.cve.org/CVERecord?id=CVE-2026-11332
- https://nvd.nist.gov/vuln/detail/CVE-2026-11332
- https://github.com/ansible/ansible
- https://access.redhat.com/security/cve/CVE-2026-12382
- https://www.cve.org/CVERecord?id=CVE-2026-12382
- https://nvd.nist.gov/vuln/detail/CVE-2026-12382
- https://access.redhat.com/security/cve/CVE-2026-12701
- https://www.cve.org/CVERecord?id=CVE-2026-12701
- https://nvd.nist.gov/vuln/detail/CVE-2026-12701
- https://access.redhat.com/security/cve/CVE-2026-25681
- https://www.cve.org/CVERecord?id=CVE-2026-25681
- https://nvd.nist.gov/vuln/detail/CVE-2026-25681
- https://go.dev/cl/781703
- https://go.dev/issue/79574
- https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
- https://pkg.go.dev/vuln/GO-2026-5029
- https://access.redhat.com/security/cve/CVE-2026-27136
- https://www.cve.org/CVERecord?id=CVE-2026-27136
- https://nvd.nist.gov/vuln/detail/CVE-2026-27136
- https://go.dev/cl/781685
- https://go.dev/issue/79575
- https://pkg.go.dev/vuln/GO-2026-5030
- https://access.redhat.com/security/cve/CVE-2026-32281
- https://www.cve.org/CVERecord?id=CVE-2026-32281
- https://nvd.nist.gov/vuln/detail/CVE-2026-32281
- https://go.dev/cl/758061
- https://go.dev/issue/78281
- https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU
- https://pkg.go.dev/vuln/GO-2026-4946
- https://access.redhat.com/security/cve/CVE-2026-33811
- https://www.cve.org/CVERecord?id=CVE-2026-33811
- https://nvd.nist.gov/vuln/detail/CVE-2026-33811
- https://go.dev/cl/767860
- https://go.dev/issue/78803
- https://groups.google.com/g/golang-announce/c/qcCIEXso47M
- https://pkg.go.dev/vuln/GO-2026-4981
- https://access.redhat.com/security/cve/CVE-2026-39821
- https://www.cve.org/CVERecord?id=CVE-2026-39821
- https://nvd.nist.gov/vuln/detail/CVE-2026-39821
- https://go.dev/cl/767220
- https://go.dev/issue/78760
- https://pkg.go.dev/vuln/GO-2026-5026
- https://access.redhat.com/security/cve/CVE-2026-42044
- https://www.cve.org/CVERecord?id=CVE-2026-42044
- https://nvd.nist.gov/vuln/detail/CVE-2026-42044
- https://github.com/axios/axios/security/advisories/GHSA-3w6x-2g7m-8v23
- https://access.redhat.com/security/cve/CVE-2026-44432
- https://www.cve.org/CVERecord?id=CVE-2026-44432
- https://nvd.nist.gov/vuln/detail/CVE-2026-44432
- https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j
- https://access.redhat.com/security/cve/CVE-2026-44486
- https://www.cve.org/CVERecord?id=CVE-2026-44486
- https://nvd.nist.gov/vuln/detail/CVE-2026-44486
- https://github.com/axios/axios/security/advisories/GHSA-j5f8-grm9-p9fc
- https://access.redhat.com/security/cve/CVE-2026-44487
- https://www.cve.org/CVERecord?id=CVE-2026-44487
- https://nvd.nist.gov/vuln/detail/CVE-2026-44487
- https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v
- https://access.redhat.com/security/cve/CVE-2026-44488
- https://www.cve.org/CVERecord?id=CVE-2026-44488
- https://nvd.nist.gov/vuln/detail/CVE-2026-44488
- https://github.com/axios/axios/security/advisories/GHSA-777c-7fjr-54vf
- https://access.redhat.com/security/cve/CVE-2026-44492
- https://www.cve.org/CVERecord?id=CVE-2026-44492
- https://nvd.nist.gov/vuln/detail/CVE-2026-44492
- https://github.com/axios/axios/security/advisories/GHSA-pjwm-pj3p-43mv
- https://access.redhat.com/security/cve/CVE-2026-44494
- https://www.cve.org/CVERecord?id=CVE-2026-44494
- https://nvd.nist.gov/vuln/detail/CVE-2026-44494
- https://github.com/axios/axios/security/advisories/GHSA-35jp-ww65-95wh
- https://access.redhat.com/security/cve/CVE-2026-44495
- https://www.cve.org/CVERecord?id=CVE-2026-44495
- https://nvd.nist.gov/vuln/detail/CVE-2026-44495
- https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw
- https://access.redhat.com/security/cve/CVE-2026-44496
- https://www.cve.org/CVERecord?id=CVE-2026-44496
- https://nvd.nist.gov/vuln/detail/CVE-2026-44496
- https://github.com/axios/axios/security/advisories/GHSA-hfxv-24rg-xrqf
- https://access.redhat.com/security/cve/CVE-2026-42215
- https://bugzilla.redhat.com/show_bug.cgi?id=2467802
- https://www.cve.org/CVERecord?id=CVE-2026-42215
- https://nvd.nist.gov/vuln/detail/CVE-2026-42215
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4
- https://access.redhat.com/security/cve/CVE-2026-42284
- https://bugzilla.redhat.com/show_bug.cgi?id=2467800
- https://www.cve.org/CVERecord?id=CVE-2026-42284
- https://nvd.nist.gov/vuln/detail/CVE-2026-42284
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485
- https://access.redhat.com/security/cve/CVE-2026-44244
- https://bugzilla.redhat.com/show_bug.cgi?id=2467804
- https://www.cve.org/CVERecord?id=CVE-2026-44244
- https://nvd.nist.gov/vuln/detail/CVE-2026-44244
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.49
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v87r-6q3f-2j67