Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
RHSA-2026:42078
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:42078
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:42078.json
JSON Data
https://api.test.osv.dev/v1/vulns/RHSA-2026:42078
Upstream
CVE-2026-11332
CVE-2026-12382
CVE-2026-12701
CVE-2026-25681
CVE-2026-27136
CVE-2026-32281
CVE-2026-33811
CVE-2026-39821
CVE-2026-42044
CVE-2026-44432
CVE-2026-44486
CVE-2026-44487
CVE-2026-44488
CVE-2026-44492
CVE-2026-44494
CVE-2026-44495
CVE-2026-44496
CVE-2026-4800
CVE-2026-6321
CVE-2026-6322
CVE-2026-8643
Related
GO-2026-4946
GO-2026-4981
GO-2026-5026
GO-2026-5029
GO-2026-5030
Published
2026-07-23T10:13:55Z
Modified
2026-07-24T10:17:14.402331434Z
Severity
9.0 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Details
References
https://access.redhat.com/errata/RHSA-2026:42078
https://access.redhat.com/security/updates/classification/#important
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading
https://bugzilla.redhat.com/show_bug.cgi?id=2453496
https://bugzilla.redhat.com/show_bug.cgi?id=2456333
https://bugzilla.redhat.com/show_bug.cgi?id=2460927
https://bugzilla.redhat.com/show_bug.cgi?id=2461624
https://bugzilla.redhat.com/show_bug.cgi?id=2466582
https://bugzilla.redhat.com/show_bug.cgi?id=2466684
https://bugzilla.redhat.com/show_bug.cgi?id=2467822
https://bugzilla.redhat.com/show_bug.cgi?id=2477154
https://bugzilla.redhat.com/show_bug.cgi?id=2480756
https://bugzilla.redhat.com/show_bug.cgi?id=2480757
https://bugzilla.redhat.com/show_bug.cgi?id=2480761
https://bugzilla.redhat.com/show_bug.cgi?id=2485379
https://bugzilla.redhat.com/show_bug.cgi?id=2487937
https://bugzilla.redhat.com/show_bug.cgi?id=2487938
https://bugzilla.redhat.com/show_bug.cgi?id=2487942
https://bugzilla.redhat.com/show_bug.cgi?id=2487943
https://bugzilla.redhat.com/show_bug.cgi?id=2487947
https://bugzilla.redhat.com/show_bug.cgi?id=2487948
https://bugzilla.redhat.com/show_bug.cgi?id=2487949
https://bugzilla.redhat.com/show_bug.cgi?id=2489126
https://bugzilla.redhat.com/show_bug.cgi?id=2490703
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42078.json
https://access.redhat.com/security/cve/CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
https://nvd.nist.gov/vuln/detail/CVE-2026-4800
https://cna.openjsf.org/security-advisories.html
https://github.com/advisories/GHSA-35jh-r3h4-6jhm
https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c
https://access.redhat.com/security/cve/CVE-2026-6321
https://www.cve.org/CVERecord?id=CVE-2026-6321
https://nvd.nist.gov/vuln/detail/CVE-2026-6321
https://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6
https://access.redhat.com/security/cve/CVE-2026-6322
https://www.cve.org/CVERecord?id=CVE-2026-6322
https://nvd.nist.gov/vuln/detail/CVE-2026-6322
https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc
https://access.redhat.com/security/cve/CVE-2026-8643
https://www.cve.org/CVERecord?id=CVE-2026-8643
https://nvd.nist.gov/vuln/detail/CVE-2026-8643
https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb
https://access.redhat.com/security/cve/CVE-2026-11332
https://www.cve.org/CVERecord?id=CVE-2026-11332
https://nvd.nist.gov/vuln/detail/CVE-2026-11332
https://github.com/ansible/ansible
https://access.redhat.com/security/cve/CVE-2026-12382
https://www.cve.org/CVERecord?id=CVE-2026-12382
https://nvd.nist.gov/vuln/detail/CVE-2026-12382
https://access.redhat.com/security/cve/CVE-2026-12701
https://www.cve.org/CVERecord?id=CVE-2026-12701
https://nvd.nist.gov/vuln/detail/CVE-2026-12701
https://access.redhat.com/security/cve/CVE-2026-25681
https://www.cve.org/CVERecord?id=CVE-2026-25681
https://nvd.nist.gov/vuln/detail/CVE-2026-25681
https://go.dev/cl/781703
https://go.dev/issue/79574
https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
https://pkg.go.dev/vuln/GO-2026-5029
https://access.redhat.com/security/cve/CVE-2026-27136
https://www.cve.org/CVERecord?id=CVE-2026-27136
https://nvd.nist.gov/vuln/detail/CVE-2026-27136
https://go.dev/cl/781685
https://go.dev/issue/79575
https://pkg.go.dev/vuln/GO-2026-5030
https://access.redhat.com/security/cve/CVE-2026-32281
https://www.cve.org/CVERecord?id=CVE-2026-32281
https://nvd.nist.gov/vuln/detail/CVE-2026-32281
https://go.dev/cl/758061
https://go.dev/issue/78281
https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU
https://pkg.go.dev/vuln/GO-2026-4946
https://access.redhat.com/security/cve/CVE-2026-33811
https://www.cve.org/CVERecord?id=CVE-2026-33811
https://nvd.nist.gov/vuln/detail/CVE-2026-33811
https://go.dev/cl/767860
https://go.dev/issue/78803
https://groups.google.com/g/golang-announce/c/qcCIEXso47M
https://pkg.go.dev/vuln/GO-2026-4981
https://access.redhat.com/security/cve/CVE-2026-39821
https://www.cve.org/CVERecord?id=CVE-2026-39821
https://nvd.nist.gov/vuln/detail/CVE-2026-39821
https://go.dev/cl/767220
https://go.dev/issue/78760
https://pkg.go.dev/vuln/GO-2026-5026
https://access.redhat.com/security/cve/CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
https://nvd.nist.gov/vuln/detail/CVE-2026-42044
https://github.com/axios/axios/security/advisories/GHSA-3w6x-2g7m-8v23
https://access.redhat.com/security/cve/CVE-2026-44432
https://www.cve.org/CVERecord?id=CVE-2026-44432
https://nvd.nist.gov/vuln/detail/CVE-2026-44432
https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j
https://access.redhat.com/security/cve/CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
https://nvd.nist.gov/vuln/detail/CVE-2026-44486
https://github.com/axios/axios/security/advisories/GHSA-j5f8-grm9-p9fc
https://access.redhat.com/security/cve/CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
https://nvd.nist.gov/vuln/detail/CVE-2026-44487
https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v
https://access.redhat.com/security/cve/CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
https://nvd.nist.gov/vuln/detail/CVE-2026-44488
https://github.com/axios/axios/security/advisories/GHSA-777c-7fjr-54vf
https://access.redhat.com/security/cve/CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
https://nvd.nist.gov/vuln/detail/CVE-2026-44492
https://github.com/axios/axios/security/advisories/GHSA-pjwm-pj3p-43mv
https://access.redhat.com/security/cve/CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
https://nvd.nist.gov/vuln/detail/CVE-2026-44494
https://github.com/axios/axios/security/advisories/GHSA-35jp-ww65-95wh
https://access.redhat.com/security/cve/CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
https://nvd.nist.gov/vuln/detail/CVE-2026-44495
https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw
https://access.redhat.com/security/cve/CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
https://nvd.nist.gov/vuln/detail/CVE-2026-44496
https://github.com/axios/axios/security/advisories/GHSA-hfxv-24rg-xrqf
Affected packages
Red Hat:ansible_automation_platform:2.5::el8
automation-gateway-server
Package
Name
automation-gateway-server
Purl
pkg:rpm/redhat/automation-gateway-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.5.20260715-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.30-2.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
ansible-core
Package
Name
ansible-core
Purl
pkg:rpm/redhat/ansible-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
python3.12-pulpcore
Package
Name
python3.12-pulpcore
Purl
pkg:rpm/redhat/python3.12-pulpcore
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.49.63-2.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor-debuginfo
Package
Name
receptor-debuginfo
Purl
pkg:rpm/redhat/receptor-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor-debugsource
Package
Name
receptor-debugsource
Purl
pkg:rpm/redhat/receptor-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
Red Hat:ansible_automation_platform:2.5::el9
automation-gateway-server
Package
Name
automation-gateway-server
Purl
pkg:rpm/redhat/automation-gateway-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.5.20260715-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.30-2.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
ansible-core
Package
Name
ansible-core
Purl
pkg:rpm/redhat/ansible-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
python3.12-pulpcore
Package
Name
python3.12-pulpcore
Purl
pkg:rpm/redhat/python3.12-pulpcore
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.49.63-2.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor-debuginfo
Package
Name
receptor-debuginfo
Purl
pkg:rpm/redhat/receptor-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor-debugsource
Package
Name
receptor-debugsource
Purl
pkg:rpm/redhat/receptor-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
Red Hat:ansible_automation_platform_developer:2.5::el8
ansible-core
Package
Name
ansible-core
Purl
pkg:rpm/redhat/ansible-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
Red Hat:ansible_automation_platform_developer:2.5::el9
ansible-core
Package
Name
ansible-core
Purl
pkg:rpm/redhat/ansible-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
Red Hat:ansible_automation_platform_inside:2.5::el8
ansible-core
Package
Name
ansible-core
Purl
pkg:rpm/redhat/ansible-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el8ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
Red Hat:ansible_automation_platform_inside:2.5::el9
ansible-core
Package
Name
ansible-core
Purl
pkg:rpm/redhat/ansible-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.16.19-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:42078.json"
RHSA-2026:42078 - OSV