Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12383— Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在事件驱动 Ansible(EDA)服务器中发现了一个漏洞。ExternalEventStreamViewSet 使用了宽松的访问控制策略(permission_classes=[AllowAny],authentication_classes=[]),仅依赖 Subject HTTP 头的值进行 mTLS 认证,而未验证该头是否来自受信任的代理。此外,预期的证书“ distinguished name”(可区分名称)会在 403 错误响应体中泄露。攻击者若能通过伪造 Subject 头访问 EDA API 端点,

CVSS 7.5 · High EPSS 0.28% · P18

Affected Version Matrix 4

VendorProduct Version RangeStatus
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:1.1.21-1.el8ap< * unaffected
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:1.1.21-1.el9ap< * unaffected
Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:1.2.11-1.el9ap< * unaffected
Red Hat Red Hat Ansible Automation Platform 2.7 1785374869< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12383

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentication without verifying that the header originated from a trusted proxy. Additionally, the expected certificate Distinguished Name is leaked in the 403 error response body. An attacker who can reach the EDA API endpoint with a spoofed Subject header can inject arbitrary events into mTLS-protected event streams, triggering downstream automation actions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:1.1.21-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:1.1.21-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:1.2.11-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el10
Red Hat Red Hat Ansible Automation Platform 2.7 1785374869 ~ * cpe:/a:redhat:ansible_automation_platform:2.7::el9

II. Public POCs for CVE-2026-12383

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12383

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-12383 (5)

Same Patch Batch · Red Hat · 2026-07-27 · 3 CVEs total

CVE-2026-17527 7.7 HIGH Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrol
CVE-2026-15003 5.6 MEDIUM Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and

IV. Related Vulnerabilities

V. Comments for CVE-2026-12383

No comments yet


Leave a comment