RHSA-2026:50319
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
CVSS Metrics
- v3.1•HIGH•Score: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected Systems
- redhat•automation-controller-venv-tower
< 0:4.6.31-1.el8ap | < 0:4.6.31-1.el9ap
- redhat•automation-eda-controller
< 0:1.1.21-1.el8ap | < 0:1.1.21-1.el9ap
- redhat•automation-eda-controller-base
< 0:1.1.21-1.el8ap | < 0:1.1.21-1.el9ap
- redhat•automation-eda-controller-base-services
< 0:1.1.21-1.el8ap | < 0:1.1.21-1.el9ap
- redhat•automation-eda-controller-event-stream-services
< 0:1.1.21-1.el8ap | < 0:1.1.21-1.el9ap
- redhat•automation-eda-controller-worker-services
< 0:1.1.21-1.el8ap | < 0:1.1.21-1.el9ap
- redhat•automation-gateway-proxy
< 0:2.5.10-7.el8ap | < 0:2.6.17-2.el9ap
- redhat•automation-gateway-proxy-debugsource
< 0:2.5.10-7.el8ap | < 0:2.6.17-2.el9ap
- redhat•automation-gateway-proxy-server
< 0:2.5.10-7.el8ap | < 0:2.6.17-2.el9ap
- redhat•automation-gateway-proxy-server-debuginfo
< 0:2.5.10-7.el8ap | < 0:2.6.17-2.el9ap
- redhat•python3.12-aiohttp
< 0:3.14.1-2.el8ap | < 0:3.14.1-2.el9ap
- redhat•python3.12-daphne
< 0:4.2.2-1.el8ap | < 0:4.2.2-1.el9ap
- redhat•python3.12-pillow
< 0:12.3.0-1.el8ap | < 0:12.3.0-1.el9ap
- redhat•python3.12-pyasn1
< 0:0.6.4-1.el8ap | < 0:0.6.4-1.el9ap
- redhat•receptor
< 0:1.6.7-1.el8ap | < 0:1.6.7-1.el9ap
- redhat•receptor-debuginfo
< 0:1.6.7-1.el8ap | < 0:1.6.7-1.el9ap
- redhat•receptor-debugsource
< 0:1.6.7-1.el8ap | < 0:1.6.7-1.el9ap
- redhat•receptorctl
< 0:1.6.7-1.el8ap | < 0:1.6.7-1.el9ap
References (112)
- https://access.redhat.com/errata/RHSA-2026:50319
- https://access.redhat.com/security/updates/classification/#important
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading
- https://bugzilla.redhat.com/show_bug.cgi?id=2467822
- https://bugzilla.redhat.com/show_bug.cgi?id=2482734
- https://bugzilla.redhat.com/show_bug.cgi?id=2484099
- https://bugzilla.redhat.com/show_bug.cgi?id=2484207
- https://bugzilla.redhat.com/show_bug.cgi?id=2484377
- https://bugzilla.redhat.com/show_bug.cgi?id=2484875
- https://bugzilla.redhat.com/show_bug.cgi?id=2489127
- https://bugzilla.redhat.com/show_bug.cgi?id=2497452
- https://bugzilla.redhat.com/show_bug.cgi?id=2497455
- https://bugzilla.redhat.com/show_bug.cgi?id=2497464
- https://bugzilla.redhat.com/show_bug.cgi?id=2497466
- https://bugzilla.redhat.com/show_bug.cgi?id=2500041
- https://bugzilla.redhat.com/show_bug.cgi?id=2500043
- https://bugzilla.redhat.com/show_bug.cgi?id=2500380
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50319.json
- https://access.redhat.com/security/cve/CVE-2026-12383
- https://www.cve.org/CVERecord?id=CVE-2026-12383
- https://nvd.nist.gov/vuln/detail/CVE-2026-12383
- https://access.redhat.com/security/cve/CVE-2026-27145
- https://www.cve.org/CVERecord?id=CVE-2026-27145
- https://nvd.nist.gov/vuln/detail/CVE-2026-27145
- https://go.dev/cl/783621
- https://go.dev/issue/79694
- https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw
- https://pkg.go.dev/vuln/GO-2026-5037
- https://access.redhat.com/security/cve/CVE-2026-33811
- https://www.cve.org/CVERecord?id=CVE-2026-33811
- https://nvd.nist.gov/vuln/detail/CVE-2026-33811
- https://go.dev/cl/767860
- https://go.dev/issue/78803
- https://groups.google.com/g/golang-announce/c/qcCIEXso47M
- https://pkg.go.dev/vuln/GO-2026-4981
- https://access.redhat.com/security/cve/CVE-2026-34993
- https://www.cve.org/CVERecord?id=CVE-2026-34993
- https://nvd.nist.gov/vuln/detail/CVE-2026-34993
- https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8
- https://access.redhat.com/security/cve/CVE-2026-40898
- https://www.cve.org/CVERecord?id=CVE-2026-40898
- https://nvd.nist.gov/vuln/detail/CVE-2026-40898
- https://github.com/quic-go/quic-go/releases/tag/v0.59.1
- https://github.com/quic-go/quic-go/security/advisories/GHSA-vvgj-x9jq-8cj9
- https://access.redhat.com/security/cve/CVE-2026-44545
- https://www.cve.org/CVERecord?id=CVE-2026-44545
- https://nvd.nist.gov/vuln/detail/CVE-2026-44545
- https://github.com/django/daphne/blob/main/CHANGELOG.txt
- https://access.redhat.com/security/cve/CVE-2026-48526
- https://www.cve.org/CVERecord?id=CVE-2026-48526
- https://nvd.nist.gov/vuln/detail/CVE-2026-48526
- https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx
- https://access.redhat.com/security/cve/CVE-2026-54059
- https://www.cve.org/CVERecord?id=CVE-2026-54059
- https://nvd.nist.gov/vuln/detail/CVE-2026-54059
- https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst
- https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x
- https://access.redhat.com/security/cve/CVE-2026-54060
- https://www.cve.org/CVERecord?id=CVE-2026-54060
- https://nvd.nist.gov/vuln/detail/CVE-2026-54060
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2
- https://access.redhat.com/security/cve/CVE-2026-55379
- https://www.cve.org/CVERecord?id=CVE-2026-55379
- https://nvd.nist.gov/vuln/detail/CVE-2026-55379
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc
- https://access.redhat.com/security/cve/CVE-2026-55380
- https://www.cve.org/CVERecord?id=CVE-2026-55380
- https://nvd.nist.gov/vuln/detail/CVE-2026-55380
- https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm
- https://access.redhat.com/security/cve/CVE-2026-59197
- https://www.cve.org/CVERecord?id=CVE-2026-59197
- https://nvd.nist.gov/vuln/detail/CVE-2026-59197
- https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1
- https://github.com/python-pillow/Pillow/pull/9695
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr
- https://access.redhat.com/security/cve/CVE-2026-59885
- https://www.cve.org/CVERecord?id=CVE-2026-59885
- https://nvd.nist.gov/vuln/detail/CVE-2026-59885
- https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj
- https://access.redhat.com/security/cve/CVE-2026-59886
- https://www.cve.org/CVERecord?id=CVE-2026-59886
- https://nvd.nist.gov/vuln/detail/CVE-2026-59886
- https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r
- https://access.redhat.com/security/cve/CVE-2026-39820
- https://bugzilla.redhat.com/show_bug.cgi?id=2467820
- https://www.cve.org/CVERecord?id=CVE-2026-39820
- https://nvd.nist.gov/vuln/detail/CVE-2026-39820
- https://go.dev/cl/759940
- https://go.dev/issue/78566
- https://pkg.go.dev/vuln/GO-2026-4986
- https://access.redhat.com/security/cve/CVE-2026-42499
- https://bugzilla.redhat.com/show_bug.cgi?id=2467809
- https://www.cve.org/CVERecord?id=CVE-2026-42499
- https://nvd.nist.gov/vuln/detail/CVE-2026-42499
- https://go.dev/cl/771520
- https://go.dev/issue/78987
- https://pkg.go.dev/vuln/GO-2026-4977
- https://access.redhat.com/security/cve/CVE-2026-42504
- https://bugzilla.redhat.com/show_bug.cgi?id=2484204
- https://www.cve.org/CVERecord?id=CVE-2026-42504
- https://nvd.nist.gov/vuln/detail/CVE-2026-42504
- https://go.dev/cl/774481
- https://go.dev/issue/79217
- https://pkg.go.dev/vuln/GO-2026-5038