Red Hat Product Errata RHSA-2026:50319 - Security Advisory Issued: 2026-08-04 Updated: 2026-08-04 RHSA-2026:50319 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 2.5 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): automation-controller: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526) automation-eda-controller: ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN (CVE-2026-12383) automation-gateway-proxy: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) python3.12-aio http: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993) python3.12-daphne: daphne: Denial of Service via excessive WebSocket message size (CVE-2026-44545) python3.12-pillow: Denial of Service via crafted PCF font data (CVE-2026-54059) python3.12-pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060) python3.12-pillow: Denial of Service via crafted BDF font file (CVE-2026-55379) python3.12-pillow: Denial of Service via crafted GD 2.x image file (CVE-2026-55380) python3.12-pillow: Native heap out-of-bounds write (CVE-2026-59197) python3.12-pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59885) python3.12-pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59886) receptor: quic-go: Denial of Service via excessive memory allocation in HTTP/3 trailers (CVE-2026-40898) receptor: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section. Solution For details on how to apply this update, refer to Ansible Automation Platform documentation. Affected Products Red Hat Ansible Automation Platform 2.5 for RHEL 9 x86_64 Red Hat Ansible Automation Platform 2.5 for RHEL 9 s390x Red Hat Ansible Automation Platform 2.5 for RHEL 9 ppc64le Red Hat Ansible Automation Platform 2.5 for RHEL 9 aarch64 Red Hat Ansible Automation Platform 2.5 for RHEL 8 x86_64 Red Hat Ansible Automation Platform 2.5 for RHEL 8 s390x Red Hat Ansible Automation Platform 2.5 for RHEL 8 ppc64le Red Hat Ansible Automation Platform 2.5 for RHEL 8 aarch64 Red Hat Ansible Inside 1.3 for RHEL 9 x86_64 Red Hat Ansible Inside 1.3 for RHEL 9 s390x Red Hat Ansible Inside 1.3 for RHEL 9 ppc64le Red Hat Ansible Inside 1.3 for RHEL 9 aarch64 Red Hat Ansible Inside 1.3 for RHEL 8 x86_64 Red Hat Ansible Inside 1.3 for RHEL 8 s390x Red Hat Ansible Inside 1.3 for RHEL 8 ppc64le Red Hat Ansible Inside 1.3 for RHEL 8 aarch64 Red Hat Ansible Developer 1.2 for RHEL 9 x86_64 Red Hat Ansible Developer 1.2 for RHEL 9 s390x Red Hat Ansible Developer 1.2 for RHEL 9 ppc64le Red Hat Ansible Developer 1.2 for RHEL 9 aarch64 Red Hat Ansible Developer 1.2 for RHEL 8 x86_64 Red Hat Ansible Developer 1.2 for RHEL 8 s390x Red Hat Ansible Developer 1.2 for RHEL 8 ppc64le Red Hat Ansible Developer 1.2 for RHEL 8 aarch64 Fixes BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2482734 - CVE-2026-48526 python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens BZ - 2484099 - CVE-2026-34993 aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() BZ - 2484207 - CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries BZ - 2484377 - CVE-2026-44545 daphne: daphne: Denial of Service via excessive WebSocket message size BZ - 2484875 - CVE-2026-40898 github.com/quic-go/quic-go: quic-go: Denial of Service via excessive memory allocation in HTTP/3 trailers BZ - 2489127 - CVE-2026-12383 eda-server: ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN BZ - 2497452 - CVE-2026-55379 python-pillow: Pillow: Denial of Service via crafted BDF font file BZ - 2497455 - CVE-2026-55380 python-pillow: Pillow: Denial of Service via crafted GD 2.x image file BZ - 2497464 - CVE-2026-54059 python-pillow: Pillow: Denial of Service via crafted PCF font data BZ - 2497466 - CVE-2026-54060 python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files BZ - 2500041 - CVE-2026-59886 pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values BZ - 2500043 - CVE-2026-59197 Pillow: Pillow: Native heap out-of-bounds write BZ - 2500380 - CVE-2026-59885 pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER CVEs CVE-2026-12383 CVE-2026-27145 CVE-2026-33811 CVE-2026-34993 CVE-2026-40898 CVE-2026-44545 CVE-2026-48526 CVE-2026-54059 CVE-2026-54060 CVE-2026-55379 CVE-2026-55380 CVE-2026-59197 CVE-2026-59885 CVE-2026-59886 References https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Ansible Automation Platform 2.5 for RHEL 9 SRPM automation-controller-4.6.31-1.el9ap.src.rpm SHA-256: 557b9007c861ecb292b0b20cf103a571aeab6c5d856d0107f8aaf84817487692 automation-eda-controller-1.1.21-1.el9ap.src.rpm SHA-256: 0f1067b0da1f2b119a60ee8f25cb6a2d015f8a1f8bff5cfa97dcfa8c63733f38 automation-gateway-2.5.20260804-1.el9ap.src.rpm SHA-256: b928bc87b4cc6c04a55025e9ecc97af0b158c40fef644fe6c570f5600203aa23 automation-gateway-proxy-2.6.17-2.el9ap.src.rpm SHA-256: f319b68f17dcaad344478d06f1b0eae1d8c4cb59bb064add271d67c6c681c79d automation-hub-4.10.17-1.el9ap.src.rpm SHA-256: 14327bff8ba652d9c6d2f3dc9902773f4fb0b48ad0f0b41a9bb8f01840698503 python3.12-aiohttp-3.14.1-2.el9ap.src.rpm SHA-256: 34d21c3dd1265716d6dd6dd4404a71933d8c5b8db214dd5bd6542a1a5913bafd python3.12-daphne-4.2.2-1.el9ap.src.rpm SHA-256: 4b269f6d42a0014d39cd8e3308d5172568e6c542dc5cbbdc760d44261cf53253 python3.12-galaxy-ng-4.10.17-1.el9ap.src.rpm SHA-256: 02f282f012729a44d5c62356f157446f5e75cc75c6c7db5ffa3c1d39ef3b6ad6 python3.12-pillow-12.3.0-1.el9ap.src.rpm SHA-256: 0c8ff020095b941d0f72d83236388933ab993440d4431a41a46eef1e47517c32 python3.12-pulpcore-3.49.66-1.el9ap.src.rpm SHA-256: 36f522c0e0475c98de6e70abd1264c1123d0128d09163a28ca9bc549ba8b9619 python3.12-pyasn1-0.6.4-1.el9ap.src.rpm SHA-256: 66bb5f2943c770b7b46feeb1297d12b025da76f9da0c17617279d5a77cd3de51 receptor-1.6.7-1.el9ap.src.rpm SHA-256: 647e2f404e7234daf43b95af9af99494ddcb98f4c5f7aed09f70ecfe48828ef5 x86_64 automation-controller-4.6.31-1.el9ap.x86_64.rpm SHA-256: a0c12ef66d87ec388ae8205f727440984566ad41f9538e8bda6f9bbdaaac25d3 automation-controller-cli-4.6.31-1.el9ap.noarch.rpm SHA-256: 21a2d93ae428a86141e52d947d55034fa9258436b58cf5a7c7e330c7bbce260d automation-controller-server-4.6.31-1.el9ap.noarch.rpm SHA-256: 3b65a16a64bc7da7aaa66a87b9d0a6ebe80b733c5bf512ae9adf10beb645fa7c automation-controller-ui-4.6.31-1.el9ap.noarch.rpm SHA-256: 7e54af0bd1d2a3cd55de209ec8f6675b093c04bc05066a19366e156a1183bb9c automation-controller-venv-tower-4.6.31-1.el9ap.x86_64.rpm SHA-256: 40af135ac66f57a4b33161901e0a72f8bdc97db26ce14ae68503482d593cb4c2 automation-eda-controller-1.1.21-1.el9ap.noarch.rpm SHA-256: 8824b4484b56fbae64758e1c49cbab5b07be5170f24091717f4e322b629d671d automation-eda-controller-base-1.1.21-1.el9ap.noarch.rpm SHA-256: a93099da4db0b69e4590f19aef4e45224922caf93d14101d30f12dfe7e4ff88d automation-eda-controller-base-services-1.1.21-1.el9ap.noarch.rpm SHA-256: df505fb2bd6a72cad3431fa894cf6eb3605feb9512d0d2b4525b5b15afeb9d77 automation-eda-controller-event-stream-services-1.1.21-1.el9ap.noarch.rpm SHA-256: 5bffba97011db65c072db1d59b8778c08794e4abe2f825d30ecad04204675d9a automation-eda-controller-worker-services-1.1.21-1.el9ap.noarch.rpm SHA-256: 793e02dd8910a4e5aa4e09ff159a22f60a09d656b3b7760a3cc8a60a9fbec1b5 automation-gateway-2.5.20260804-1.el9ap.noarch.rpm SHA-256: 859736c588b6285fdb7a667dd38f43ca68fa892f5001d4f4ef0685a7007a3db9 automation-gateway-config-2.5.20260804-1.el9ap.noarch.rpm SHA-256: 0d3d258d7929c63879ecd42a77c8166366bc8579ef3ccb1f0c1223934f9b9584 automation-gateway-proxy-2.6.17-2.el9ap.x86_64.rpm SHA-256: f489f3b1cf798aa6cc22b746fd36eaf7d25b63354f63acbbebfde3de4c086258 automation-gateway-proxy-debugsource-2.6.17-2.el9ap.x86_64.rpm SHA-256: 2588f2625cfabf32087fd77bdafca9dbe8b9ab3196dcc4da911c20ec73015bd4 automation-gateway-proxy-server-2.6.17-2.el9ap.x86_64.rpm SHA-256: 32a5e450820780e2db9c345fa5aa21181fc8d8f54969d8736efce08fa818b1da automation-gateway-proxy-server-debuginfo-2.6.17-2.el9ap.x86_64.rpm SHA-256: c6acf107f9c1885b90466c53f76e95b0c233953dc
This Red Hat Security Advisory addresses multiple high-severity vulnerabilities (CVSS scores up to 7.5) in Ansible Automation Platform 2.5, including an authentication bypass in PyJWT (CVE-2026-48526, CVSS 7.4), denial-of-service flaws in Go's net package and quic-go, and arbitrary code execution in python3.12-aiohttp. The update provides fixes for these issues within the platform's bundled components. IT professionals should apply the Red Hat-provided patch for Ansible Automation Platform 2.5 immediately.