A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23518
https://bugzilla.redhat.com/show_bug.cgi?id=2371644