Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:24762: Important: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update

  • What: Security and bug fix update for Ansible Automation Platform 2.6
  • Impact: Red Hat Ansible Automation Platform users
Read Full Article →

Red Hat Product Errata RHSA-2026:24762 - Security Advisory Issued: 2026-06-09 Updated: 2026-06-09 RHSA-2026:24762 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 2.6 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): automation-controller: Cryptography: Buffer overflow via non-contiguous buffer in API (CVE-2026-39892) automation-controller: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922) automation-gateway-proxy: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) automation-gateway-proxy: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) automation-platform-ui: Vite: Information disclosure via WebSocket connection bypasses access control (CVE-2026-39363) automation-platform-ui: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800) automation-platform-ui: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() (CVE-2026-33891) automation-platform-ui: path-to-regexp: Denial of Service via crafted regular expressions (CVE-2026-4926) automation-platform-ui: Axios: Remote Code Execution via Prototype Pollution escalation (CVE-2026-40175) python-click/python3.12-click: Pallets Click: Arbitrary command execution via command injection in click.edit() (CVE-2026-7246) python3.12-cryptography: Buffer overflow via non-contiguous buffer in API (CVE-2026-39892) python3.12-pillow: Denial of Service via decompression bomb in FITS image processing (CVE-2026-40192) receptor: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) receptor: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) receptor: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section. Solution For details on how to apply this update, refer to Ansible Automation Platform documentation. Affected Products Red Hat Ansible Automation Platform 2.6 for RHEL 10 x86_64 Red Hat Ansible Automation Platform 2.6 for RHEL 10 s390x Red Hat Ansible Automation Platform 2.6 for RHEL 10 ppc64le Red Hat Ansible Automation Platform 2.6 for RHEL 10 aarch64 Red Hat Ansible Automation Platform 2.6 for RHEL 9 x86_64 Red Hat Ansible Automation Platform 2.6 for RHEL 9 s390x Red Hat Ansible Automation Platform 2.6 for RHEL 9 ppc64le Red Hat Ansible Automation Platform 2.6 for RHEL 9 aarch64 Red Hat Ansible Inside 1.4 x86_64 Red Hat Ansible Inside 1.4 s390x Red Hat Ansible Inside 1.4 ppc64le Red Hat Ansible Inside 1.4 aarch64 Red Hat Ansible Developer 1.3 for RHEL 10 x86_64 Red Hat Ansible Developer 1.3 for RHEL 10 s390x Red Hat Ansible Developer 1.3 for RHEL 10 ppc64le Red Hat Ansible Developer 1.3 for RHEL 10 aarch64 Red Hat Ansible Developer 1.3 for RHEL 9 x86_64 Red Hat Ansible Developer 1.3 for RHEL 9 s390x Red Hat Ansible Developer 1.3 for RHEL 9 ppc64le Red Hat Ansible Developer 1.3 for RHEL 9 aarch64 Fixes BZ - 2448553 - CVE-2026-30922 pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion BZ - 2451867 - CVE-2026-4926 path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions BZ - 2452450 - CVE-2026-33891 node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() BZ - 2453496 - CVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template imports BZ - 2456179 - CVE-2026-39363 Vite: Vite: Information disclosure via WebSocket connection bypasses access control BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building BZ - 2456735 - CVE-2026-39892 cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API BZ - 2457432 - CVE-2026-40175 axios: Axios: Remote Code Execution via Prototype Pollution escalation BZ - 2458856 - CVE-2026-40192 Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing BZ - 2464121 - CVE-2026-7246 github.com/pallets/click: Pallets Click: Arbitrary command execution via command injection in click.edit() CVEs CVE-2026-4800 CVE-2026-4926 CVE-2026-7246 CVE-2026-30922 CVE-2026-32280 CVE-2026-32282 CVE-2026-32283 CVE-2026-33891 CVE-2026-39363 CVE-2026-39892 CVE-2026-40175 CVE-2026-40192 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updates https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Ansible Automation Platform 2.6 for RHEL 10 SRPM ansible-creator-26.4.3-2.el10ap.src.rpm SHA-256: 0afd98af428c9cea75ccfca4d44aa2a4cce4c6bba05016ac4c7d72b9555f6b4c ansible-dev-environment-26.4.0-2.el10ap.src.rpm SHA-256: 80a7cfce20a4c1822bdc19df103df4494631946aa71b2f995bda657c3b38bf01 ansible-dev-tools-26.4.6-1.el10ap.src.rpm SHA-256: 98789e606157c9dc178c93400f61c61ca3abe6b5d626329e2fda06167c335fe4 ansible-lint-26.4.0-1.el10ap.src.rpm SHA-256: d2e04fa3e9f030959c263d38cc88b1cc12abf95db0d0beeae98d072915d1d5e9 ansible-navigator-26.4.0-2.el10ap.src.rpm SHA-256: ab95e951fccb79cbc9741bf212cc70516595d7001e1442e351e0a081d410d748 ansible-sign-0.1.5-1.el10ap.src.rpm SHA-256: efd66a89e672d1d2bfa2b4229d7103d77ae3405b438c195a9b7997010bec459d molecule-26.4.0-2.el10ap.src.rpm SHA-256: 11d213f76ae5215033de8aa9a21e03ae96fb967d361fb4b9f43b8d66451a741a python-ansible-compat-26.3.0-2.el10ap.src.rpm SHA-256: 98c09d445afe65e935cfc9fb5cd4d9f419da99ef25123af41e365fb98d5ac06b python-click-8.3.3-1.el10ap.src.rpm SHA-256: 288df9c37e54e38f85d4ff343e9bd5e56ecf585790aa5787b90860502730629b python-pytest-ansible-26.4.0-1.el10ap.src.rpm SHA-256: 7d132053d39e74db187e98ab6fb5dfaf4debd7149e224e8a5d974e568e13e264 python-tox-ansible-26.3.0-2.el10ap.src.rpm SHA-256: 0bfa5feba41f8ef59abba0c53ebc0501a9c77bd26e7a0a417f5b0f1b79b8459c receptor-1.6.5-1.el10ap.src.rpm SHA-256: f4f9ec1b2bc66d4f6ba2ba90fa2c846a3f6548670b5bf8217e65bcef2497277d x86_64 ansible-creator-26.4.3-2.el10ap.noarch.rpm SHA-256: a27abfedaea215202138a0366f769df26110dc374ae93f4bc0a0f12d5a041563 ansible-dev-environment-26.4.0-2.el10ap.noarch.rpm SHA-256: c4b36f66b01c608aada378958c531bf92ec1c9fe061277604b03572dafb11881 ansible-dev-tools+server-26.4.6-1.el10ap.noarch.rpm SHA-256: de27302451f55ba0dfbedf99042e7f0e25e422054e4852e40e4491e20ebdb50e ansible-dev-tools-26.4.6-1.el10ap.noarch.rpm SHA-256: 007fae826286543dbff7a930fded95e030b221ef9249b6533e70aeab09f7f200 ansible-lint-26.4.0-1.el10ap.noarch.rpm SHA-256: a88ad1eb476f2f799ab35e2ec6bde6195805a053a6be924325c53b31654f88b3 ansible-navigator-26.4.0-2.el10ap.noarch.rpm SHA-256: 7f5e65fdc92faeb221bb1f92fcf1284e6722ace1064e4d0aa0942b58a677e8cd ansible-sign-0.1.5-1.el10ap.noarch.rpm SHA-256: 6d20b9804d7982efb972cdb9066ce2a6b0ac8fe972f5caa24f56dffe80a00544 molecule-26.4.0-2.el10ap.noarch.rpm SHA-256: 825bf13962bcdebd02eaf42b5e95a15bd767f2dff7a273804af646f5a39e333e python3-ansible-compat-26.3.0-2.el10ap.noarch.rpm SHA-256: 21735e85394ae76f597e990f476235217d1214f01f8867048d1ec933045300d6 python3-click-8.3.3-1.el10ap.noarch.rpm SHA-256: cd806ef99922204edff754408a0cd1e52c88342d166b6f568db62955c9c9e3d3 python3-pytest-ansible-26.4.0-1.el10ap.noarch.rpm SHA-256: fea372f3fa6f83c3cf49e7bd7de14f77dc7d5bdcb42c33c7c7d52d6ab5565c09 python3-tox-ansible-26.3.0-2.el10ap.noarch.rpm SHA-256: 9279ef984e54bf9caefcf5bf2caf72793277b4ed19974ed7058556ea0e87a1a7 receptor-1.6.5-1.el10ap.x86_64.rpm SHA-256: fbe05f50d234a6bca3543014419f5d274479967df45214ca22bb762255bd768a receptor-debuginfo-1.6.5-1.el10ap.x86_64.rpm SHA-256: 55573a17b001d788b93ce9b9289f9281f4958ca37d4bd60579882b5a2c849d2a receptor-debugsource-1.6.5-1.el10ap.x86_64.rpm SHA-256: 5690f36f69dfe583cd73ce84994a3270e83e2f7efebee29165cdc9a6483addad receptorctl-1.6.5-1.el10ap.noarch.rpm SHA-256: b975548e164fdceb22c67866537204ef9f2aee581a124c832c237f97b0f7a12e s390x ansible-creator-26.4.3-2.el10ap.noarch.rpm SHA-256: a27abfedaea215202138a0366f769df26110dc374ae93f4bc0a0f12d5a041563 ansible-dev-environment-26.4.0-2.el10ap.noarch.rpm SHA-256: c4b36f66b01c608aada378958c531bf92ec1c9fe061277604b03572dafb11881 ansible-dev-tools+server-26.4.6-1.el10ap.noarch.rpm SHA-256: de27302451f55ba0dfbedf99042e7f0e25e422054e4852e40e4491e20ebdb50e ansible-dev-tools-26.4.6-1.el10ap.noarch.rpm SHA-256: 007fae826286543dbff7a930fded

Share this article