Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Ansible Automation Platform 2 — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in Red Hat Ansible Automation Platform 2, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting Red Hat Ansible Automation Platform 2, a specific software product developed by Red Hat. It catalogs security flaws identified in the platform, including those related to its underlying components, automation engine, and user interface. The data covers a broad range of weakness types, such as remote code execution, privilege escalation, denial of service, and information disclosure, spanning from initial releases through recent updates. Readers can utilize this resource to track Red Hat’s security advisories for this product line, understand the prevalence of specific weakness classes within the automation ecosystem, and review the historical vulnerability landscape of Ansible Automation Platform 2. By analyzing these aggregated records, security professionals can identify patterns in reported issues, assess the risk posture of their own deployments, and verify that their instances are patched against known defects. The collection serves as a neutral reference point for auditing compliance and verifying that system administrators have applied all relevant fixes documented by the vendor or discovered through external research. This aggregation facilitates a comprehensive view of the product’s security trajectory without relying on scattered individual announcements.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-90959 Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theft CWE-22 8.1 High 2026-09-24
CVE-2026-94416 Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery CWE-290 6.8 Medium 2026-09-24
CVE-2026-92091 Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops array CWE-407 5.9 Medium 2026-09-16
CVE-2026-79699 Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacement of extraction destination directory CWE-59 4.4 Medium 2026-09-15
CVE-2026-79705 Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers CWE-22 4.5 Medium 2026-09-15
CVE-2026-84185 Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification CWE-347 5.9 Medium 2026-09-03
CVE-2026-84232 Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content CWE-79 5.4 Medium 2026-09-01
CVE-2026-80179 Jwcrypto: jwcrypto: denial of service via malformed jwe tokens CWE-770 5.9 Medium 2026-08-27
CVE-2026-79717 Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restriction CWE-918 6.4 Medium 2026-08-25
CVE-2026-44191 Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settings CWE-78 7.8 High 2026-07-22
CVE-2026-44187 Ansible-lightspeed: ansible lightspeed extension for visual studio code: information disclosure of google gemini api key CWE-256 3.3 Low 2026-07-22
CVE-2026-44192 Ansible-lightspeed: ansible lightspeed mcp server: remote code execution and data exfiltration via path traversal CWE-22 6.6 Medium 2026-07-22
CVE-2026-44190 Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script setting CWE-78 7.8 High 2026-07-22
CVE-2026-44189 Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filename CWE-88 7.8 High 2026-07-22
CVE-2026-16544 Awx: websocket eventconsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure CWE-862 6.5 Medium 2026-07-22
CVE-2026-12726 Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credential CWE-918 6.3 Medium 2026-06-19
CVE-2026-12398 Galaxy_ng: shell injection in legacy role import via unsanitized git ref names CWE-78 7.5 High 2026-06-16
CVE-2026-6494 Aap-mcp-server: aap mcp server: log injection allows social engineering attacks via unsanitized input CWE-117 5.3 Medium 2026-04-17
CVE-2025-53861 Aap: sensitive cookie(s) set without security flags CWE-319 3.1 Low 2025-07-11
CVE-2025-53862 Aap: aap-gateway: automation-hub: sensitive information disclosure CWE-497 3.5 Low 2025-07-11

All 20 known CVE vulnerabilities affecting Red Hat Ansible Automation Platform 2 with full Chinese analysis, references, and POCs where available.