Red hat ansible automation platform 2.5 for rhel 8
This hub aggregates every CVE we track for Red hat ansible automation platform 2.5 for rhel 8, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
21
CVEs tracked
2
Critical
8
High
0
In CISA KEV
Severity distribution
MEDIUM11HIGH8CRITICAL2
Monthly trend
1
1
3
0
0
0
2
0
0
2
1
1
0
0
0
0
1
3
0
0
1
2
3
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat ansible automation platform 2.5 for rhel 8.
- CVE-2026-12383Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn7.5
- CVE-2026-12701Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport9.0
- CVE-2026-12382Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing8.2
- CVE-2026-11807Eda-server: websocket missing authorization allows credential theft via activation_id spoofing9.6
- CVE-2026-11332Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution7.8
- CVE-2026-6266Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified email linking8.3
- CVE-2025-9909Aap-gateway: improper path validation in gateway allows credential exfiltration6.7
- CVE-2025-9908Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams6.7
- CVE-2025-9907Event-driven-ansible: event stream test mode exposes sensitive headers in aap eda6.7
- CVE-2025-14025Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions8.5
- CVE-2025-5988Aap-gateway: csrf origin checking is disabled5.3
- CVE-2025-7738Python3.11-django-ansible-base: sensitive authenticator secrets returned in clear text via api in aap4.4
- CVE-2025-49520Event-driven-ansible: authenticated argument injection in git url in eda project creation8.8
- CVE-2025-49521Event-driven-ansible: template injection via git branch and refspec in eda projects8.8
- CVE-2025-2877Event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in eda6.5
Product normalization is registry-driven with AI assist and human review. How it works