RHEL 8 / 9 : Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update (Important) (RHSA-2026:42078)

high Nessus Plugin ID 328365

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 8 / 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2026:42078 advisory.

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.

Security Fix(es):

* ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution (CVE-2026-11332)
* automation-controller: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (CVE-2026-8643)
* automation-controller: urllib3: Denial of Service due to excessive HTTP response decompression (CVE-2026-44432)
* automation-gateway: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization (CVE-2026-44492)
* automation-gateway: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name (CVE-2026-44496)
* automation-gateway: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution (CVE-2026-44494)
* automation-gateway: Axios: Information disclosure of proxy credentials via HTTP redirects (CVE-2026-44486)
* automation-gateway: Axios: Information disclosure of proxy credentials via redirect flows (CVE-2026-44487)
* automation-gateway: Axios: Denial of Service due to unenforced request and response size limits (CVE-2026-44488)
* automation-gateway: Axios: Information disclosure due to prototype pollution vulnerability (CVE-2026-44495)
* automation-gateway: fast-uri: URI authority bypass due to improper delimiter handling (CVE-2026-6322)
* automation-gateway: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget (CVE-2026-42044)
* automation-gateway: fast-uri: Path traversal vulnerability allows bypass of security policies (CVE-2026-6321)
* automation-gateway: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)
* automation-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing (CVE-2026-12382)
* python3.12-pulpcore: relative_path_validator bypass via directory traversal in FilesystemExport (CVE-2026-12701)
* receptor: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
* receptor: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
* receptor: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
* receptor: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
* receptor: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

For details about this release, refer to the release notes listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/errata/RHSA-2026:42078

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2453496

https://bugzilla.redhat.com/show_bug.cgi?id=2456333

https://bugzilla.redhat.com/show_bug.cgi?id=2460927

https://bugzilla.redhat.com/show_bug.cgi?id=2461624

https://bugzilla.redhat.com/show_bug.cgi?id=2466582

https://bugzilla.redhat.com/show_bug.cgi?id=2466684

https://bugzilla.redhat.com/show_bug.cgi?id=2467822

https://bugzilla.redhat.com/show_bug.cgi?id=2477154

https://bugzilla.redhat.com/show_bug.cgi?id=2480756

https://bugzilla.redhat.com/show_bug.cgi?id=2480757

https://bugzilla.redhat.com/show_bug.cgi?id=2480761

https://bugzilla.redhat.com/show_bug.cgi?id=2485379

https://bugzilla.redhat.com/show_bug.cgi?id=2487937

https://bugzilla.redhat.com/show_bug.cgi?id=2487938

https://bugzilla.redhat.com/show_bug.cgi?id=2487942

https://bugzilla.redhat.com/show_bug.cgi?id=2487943

https://bugzilla.redhat.com/show_bug.cgi?id=2487947

https://bugzilla.redhat.com/show_bug.cgi?id=2487948

https://bugzilla.redhat.com/show_bug.cgi?id=2487949

https://bugzilla.redhat.com/show_bug.cgi?id=2489126

https://bugzilla.redhat.com/show_bug.cgi?id=2490703

http://www.nessus.org/u?62d0056d

http://www.nessus.org/u?8a5ccf41

http://www.nessus.org/u?de4ef659

Plugin Details

Severity: High

ID: 328365

File Name: redhat-RHSA-2026-42078.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/20/2026

Updated: 7/20/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.47

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-4800

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.9

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

CVSS Score Source: CVE-2026-44432

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:8, cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:ansible-core, p-cpe:/a:redhat:enterprise_linux:automation-controller-venv-tower, p-cpe:/a:redhat:enterprise_linux:automation-gateway-server, p-cpe:/a:redhat:enterprise_linux:python3.12-pulpcore, p-cpe:/a:redhat:enterprise_linux:receptor, p-cpe:/a:redhat:enterprise_linux:receptorctl

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/20/2026

Vulnerability Publication Date: 3/31/2026

Reference Information

CVE: CVE-2026-11332, CVE-2026-12382, CVE-2026-12701, CVE-2026-25681, CVE-2026-27136, CVE-2026-32281, CVE-2026-33811, CVE-2026-39821, CVE-2026-42044, CVE-2026-44432, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496, CVE-2026-4800, CVE-2026-6321, CVE-2026-6322, CVE-2026-8643

CWE: 1050, 1289, 1333, 1341, 140, 201, 22, 289, 290, 409, 770, 79, 88, 915, 94

IAVA: 2026-A-0666

RHSA: 2026:42078