RHSA-2026:6277
Advisory lineage Upstream: 7 Downstream: 0
Published: 01 Apr 2026, 10:07
Last modified:19 Sept 2026, 10:13
Vulnerability Summary
Overall Risk (default)
medium
30/100 CVSS Score
7.5 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
01 Apr 2026, 10:07
Published
Vulnerability first disclosed
19 Sept 2026, 10:13
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Systems
- redhat•automation-gateway-proxy
< 0:2.6.14-1.el9
- redhat•automation-gateway-proxy-debugsource
< 0:2.6.14-1.el9
- redhat•automation-gateway-proxy-server
< 0:2.6.14-1.el9
- redhat•automation-gateway-proxy-server-debuginfo
< 0:2.6.14-1.el9
- redhat•automation-platform-ui
< 0:2.6.7-1.el9ap
- redhat•python3.12-pillow
< 0:12.1.1-1.el9ap
- redhat•python3.12-pillow-debuginfo
< 0:12.1.1-1.el9ap
- redhat•python3.12-pillow-debugsource
< 0:12.1.1-1.el9ap
References (49)
- https://access.redhat.com/errata/RHSA-2026:6277
- https://access.redhat.com/security/updates/classification/#important
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/html/release_notes/patch_releases
- https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade
- https://bugzilla.redhat.com/show_bug.cgi?id=2434432
- https://bugzilla.redhat.com/show_bug.cgi?id=2437111
- https://bugzilla.redhat.com/show_bug.cgi?id=2438237
- https://bugzilla.redhat.com/show_bug.cgi?id=2439070
- https://bugzilla.redhat.com/show_bug.cgi?id=2439170
- https://bugzilla.redhat.com/show_bug.cgi?id=2442922
- https://bugzilla.redhat.com/show_bug.cgi?id=2445132
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6277.json
- https://access.redhat.com/security/cve/CVE-2025-61726
- https://www.cve.org/CVERecord?id=CVE-2025-61726
- https://nvd.nist.gov/vuln/detail/CVE-2025-61726
- https://go.dev/cl/736712
- https://go.dev/issue/77101
- https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
- https://pkg.go.dev/vuln/GO-2026-4341
- https://access.redhat.com/security/cve/CVE-2025-68121
- https://www.cve.org/CVERecord?id=CVE-2025-68121
- https://nvd.nist.gov/vuln/detail/CVE-2025-68121
- https://go.dev/cl/737700
- https://go.dev/issue/77217
- https://groups.google.com/g/golang-announce/c/K09ubi9FQFk
- https://pkg.go.dev/vuln/GO-2026-4337
- https://access.redhat.com/security/cve/CVE-2025-69873
- https://www.cve.org/CVERecord?id=CVE-2025-69873
- https://nvd.nist.gov/vuln/detail/CVE-2025-69873
- https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md
- https://access.redhat.com/security/cve/CVE-2026-25639
- https://www.cve.org/CVERecord?id=CVE-2026-25639
- https://nvd.nist.gov/vuln/detail/CVE-2026-25639
- https://github.com/axios/axios/commit/28c721588c7a77e7503d0a434e016f852c597b57
- https://github.com/axios/axios/releases/tag/v1.13.5
- https://github.com/axios/axios/security/advisories/GHSA-43fc-jf86-j433
- https://access.redhat.com/security/cve/CVE-2026-25990
- https://www.cve.org/CVERecord?id=CVE-2026-25990
- https://nvd.nist.gov/vuln/detail/CVE-2026-25990
- https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc
- https://access.redhat.com/security/cve/CVE-2026-27904
- https://www.cve.org/CVERecord?id=CVE-2026-27904
- https://nvd.nist.gov/vuln/detail/CVE-2026-27904
- https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74
- https://access.redhat.com/security/cve/CVE-2026-29074
- https://www.cve.org/CVERecord?id=CVE-2026-29074
- https://nvd.nist.gov/vuln/detail/CVE-2026-29074
- https://github.com/svg/svgo/security/advisories/GHSA-xpqw-6gx7-v673