Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
RHSA-2026:24761
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:24761
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:24761.json
JSON Data
https://api.test.osv.dev/v1/vulns/RHSA-2026:24761
Upstream
CVE-2025-62718
CVE-2026-26996
CVE-2026-27904
CVE-2026-30922
CVE-2026-32280
CVE-2026-32282
CVE-2026-32283
CVE-2026-33891
CVE-2026-33894
CVE-2026-33895
CVE-2026-33896
CVE-2026-39363
CVE-2026-39892
CVE-2026-40192
CVE-2026-4926
CVE-2026-7246
Related
GO-2026-4864
GO-2026-4870
GO-2026-4947
Published
2026-06-10T10:07:59Z
Modified
2026-06-11T10:17:41.636152126Z
Severity
7.8 (High)
CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Details
References
https://access.redhat.com/errata/RHSA-2026:24761
https://access.redhat.com/security/updates/classification/#important
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading
https://bugzilla.redhat.com/show_bug.cgi?id=2441268
https://bugzilla.redhat.com/show_bug.cgi?id=2442922
https://bugzilla.redhat.com/show_bug.cgi?id=2448553
https://bugzilla.redhat.com/show_bug.cgi?id=2451867
https://bugzilla.redhat.com/show_bug.cgi?id=2452450
https://bugzilla.redhat.com/show_bug.cgi?id=2452457
https://bugzilla.redhat.com/show_bug.cgi?id=2452458
https://bugzilla.redhat.com/show_bug.cgi?id=2452464
https://bugzilla.redhat.com/show_bug.cgi?id=2456179
https://bugzilla.redhat.com/show_bug.cgi?id=2456336
https://bugzilla.redhat.com/show_bug.cgi?id=2456338
https://bugzilla.redhat.com/show_bug.cgi?id=2456339
https://bugzilla.redhat.com/show_bug.cgi?id=2456735
https://bugzilla.redhat.com/show_bug.cgi?id=2456913
https://bugzilla.redhat.com/show_bug.cgi?id=2458856
https://bugzilla.redhat.com/show_bug.cgi?id=2464121
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_24761.json
https://access.redhat.com/security/cve/CVE-2025-62718
https://www.cve.org/CVERecord?id=CVE-2025-62718
https://nvd.nist.gov/vuln/detail/CVE-2025-62718
https://datatracker.ietf.org/doc/html/rfc1034#section-3.1
https://datatracker.ietf.org/doc/html/rfc3986#section-3.2.2
https://github.com/axios/axios/commit/fb3befb6daac6cad26b2e54094d0f2d9e47f24df
https://github.com/axios/axios/pull/10661
https://github.com/axios/axios/releases/tag/v1.15.0
https://github.com/axios/axios/security/advisories/GHSA-3p68-rc4w-qgx5
https://access.redhat.com/security/cve/CVE-2026-4926
https://www.cve.org/CVERecord?id=CVE-2026-4926
https://nvd.nist.gov/vuln/detail/CVE-2026-4926
https://cna.openjsf.org/security-advisories.html
https://access.redhat.com/security/cve/CVE-2026-7246
https://www.cve.org/CVERecord?id=CVE-2026-7246
https://nvd.nist.gov/vuln/detail/CVE-2026-7246
https://github.com/pallets/click/releases/tag/8.3.3
https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
https://access.redhat.com/security/cve/CVE-2026-26996
https://www.cve.org/CVERecord?id=CVE-2026-26996
https://nvd.nist.gov/vuln/detail/CVE-2026-26996
https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5
https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26
https://access.redhat.com/security/cve/CVE-2026-27904
https://www.cve.org/CVERecord?id=CVE-2026-27904
https://nvd.nist.gov/vuln/detail/CVE-2026-27904
https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74
https://access.redhat.com/security/cve/CVE-2026-30922
https://www.cve.org/CVERecord?id=CVE-2026-30922
https://nvd.nist.gov/vuln/detail/CVE-2026-30922
https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r
https://access.redhat.com/security/cve/CVE-2026-32280
https://www.cve.org/CVERecord?id=CVE-2026-32280
https://nvd.nist.gov/vuln/detail/CVE-2026-32280
https://go.dev/cl/758320
https://go.dev/issue/78282
https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU
https://pkg.go.dev/vuln/GO-2026-4947
https://access.redhat.com/security/cve/CVE-2026-32282
https://www.cve.org/CVERecord?id=CVE-2026-32282
https://nvd.nist.gov/vuln/detail/CVE-2026-32282
https://go.dev/cl/763761
https://go.dev/issue/78293
https://pkg.go.dev/vuln/GO-2026-4864
https://access.redhat.com/security/cve/CVE-2026-32283
https://www.cve.org/CVERecord?id=CVE-2026-32283
https://nvd.nist.gov/vuln/detail/CVE-2026-32283
https://go.dev/cl/763767
https://go.dev/issue/78334
https://pkg.go.dev/vuln/GO-2026-4870
https://access.redhat.com/security/cve/CVE-2026-33891
https://www.cve.org/CVERecord?id=CVE-2026-33891
https://nvd.nist.gov/vuln/detail/CVE-2026-33891
https://github.com/digitalbazaar/forge/commit/9bb8d67b99d17e4ebb5fd7596cd699e11f25d023
https://github.com/digitalbazaar/forge/security/advisories/GHSA-5m6q-g25r-mvwx
https://access.redhat.com/security/cve/CVE-2026-33894
https://www.cve.org/CVERecord?id=CVE-2026-33894
https://nvd.nist.gov/vuln/detail/CVE-2026-33894
https://datatracker.ietf.org/doc/html/rfc2313#section-8
https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp
https://mailarchive.ietf.org/arch/msg/openpgp/5rnE9ZRN1AokBVj3VqblGlP63QE
https://www.rfc-editor.org/rfc/rfc8017.html
https://access.redhat.com/security/cve/CVE-2026-33895
https://www.cve.org/CVERecord?id=CVE-2026-33895
https://nvd.nist.gov/vuln/detail/CVE-2026-33895
https://datatracker.ietf.org/doc/html/rfc8032#section-8.4
https://github.com/digitalbazaar/forge/commit/bdecf11571c9f1a487cc0fe72fe78ff6dfa96b85
https://github.com/digitalbazaar/forge/security/advisories/GHSA-q67f-28xg-22rw
https://access.redhat.com/security/cve/CVE-2026-33896
https://www.cve.org/CVERecord?id=CVE-2026-33896
https://nvd.nist.gov/vuln/detail/CVE-2026-33896
https://github.com/digitalbazaar/forge/commit/2e492832fb25227e6b647cbe1ac981c123171e90
https://github.com/digitalbazaar/forge/security/advisories/GHSA-2328-f5f3-gj25
https://access.redhat.com/security/cve/CVE-2026-39363
https://www.cve.org/CVERecord?id=CVE-2026-39363
https://nvd.nist.gov/vuln/detail/CVE-2026-39363
https://github.com/vitejs/vite/security/advisories/GHSA-p9ff-h696-f583
https://access.redhat.com/security/cve/CVE-2026-39892
https://www.cve.org/CVERecord?id=CVE-2026-39892
https://nvd.nist.gov/vuln/detail/CVE-2026-39892
http://www.openwall.com/lists/oss-security/2026/04/08/12
https://github.com/pyca/cryptography/commit/622d672e429a7cff836a23c5903683dbec1901f5
https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq
https://access.redhat.com/security/cve/CVE-2026-40192
https://www.cve.org/CVERecord?id=CVE-2026-40192
https://nvd.nist.gov/vuln/detail/CVE-2026-40192
https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628
https://github.com/python-pillow/Pillow/pull/9521
https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j
https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb
Affected packages
Red Hat:ansible_automation_platform:2.5::el8
automation-gateway-server
Package
Name
automation-gateway-server
Purl
pkg:rpm/redhat/automation-gateway-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.5.20260422-3.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-click
Package
Name
python3.12-click
Purl
pkg:rpm/redhat/python3.12-click
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.3.3-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.29-2.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
automation-gateway-proxy-server
Package
Name
automation-gateway-proxy-server
Purl
pkg:rpm/redhat/automation-gateway-proxy-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.5.10-6.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.5-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-cryptography
Package
Name
python3.12-cryptography
Purl
pkg:rpm/redhat/python3.12-cryptography
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:46.0.7-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-pillow
Package
Name
python3.12-pillow
Purl
pkg:rpm/redhat/python3.12-pillow
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:12.2.0-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
Red Hat:ansible_automation_platform:2.5::el9
automation-gateway-server
Package
Name
automation-gateway-server
Purl
pkg:rpm/redhat/automation-gateway-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.5.20260422-3.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-click
Package
Name
python3.12-click
Purl
pkg:rpm/redhat/python3.12-click
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.3.3-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.29-2.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
automation-gateway-proxy-server
Package
Name
automation-gateway-proxy-server
Purl
pkg:rpm/redhat/automation-gateway-proxy-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.6.14-3.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.5-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-cryptography
Package
Name
python3.12-cryptography
Purl
pkg:rpm/redhat/python3.12-cryptography
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:46.0.7-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-pillow
Package
Name
python3.12-pillow
Purl
pkg:rpm/redhat/python3.12-pillow
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:12.2.0-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
Red Hat:ansible_automation_platform_developer:2.5::el8
python3.12-click
Package
Name
python3.12-click
Purl
pkg:rpm/redhat/python3.12-click
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.3.3-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.29-2.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.5-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-cryptography
Package
Name
python3.12-cryptography
Purl
pkg:rpm/redhat/python3.12-cryptography
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:46.0.7-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
Red Hat:ansible_automation_platform_developer:2.5::el9
python3.12-click
Package
Name
python3.12-click
Purl
pkg:rpm/redhat/python3.12-click
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.3.3-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.29-2.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.5-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-cryptography
Package
Name
python3.12-cryptography
Purl
pkg:rpm/redhat/python3.12-cryptography
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:46.0.7-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
Red Hat:ansible_automation_platform_inside:2.5::el8
python3.12-click
Package
Name
python3.12-click
Purl
pkg:rpm/redhat/python3.12-click
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.3.3-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.5-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-cryptography
Package
Name
python3.12-cryptography
Purl
pkg:rpm/redhat/python3.12-cryptography
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:46.0.7-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
Red Hat:ansible_automation_platform_inside:2.5::el9
python3.12-click
Package
Name
python3.12-click
Purl
pkg:rpm/redhat/python3.12-click
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.3.3-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.5-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
python3.12-cryptography
Package
Name
python3.12-cryptography
Purl
pkg:rpm/redhat/python3.12-cryptography
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:46.0.7-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:24761.json"
RHSA-2026:24761 - OSV