{"id":"RHSA-2026:50319","summary":"Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update","modified":"2026-08-06T10:13:56Z","published":"2026-08-05T10:37:39Z","related":["GO-2026-4981","GO-2026-5037"],"upstream":["CVE-2026-12383","CVE-2026-27145","CVE-2026-33811","CVE-2026-34993","CVE-2026-40898","CVE-2026-44545","CVE-2026-48526","CVE-2026-54059","CVE-2026-54060","CVE-2026-55379","CVE-2026-55380","CVE-2026-59197","CVE-2026-59885","CVE-2026-59886"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:50319"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"ARTICLE","url":"https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releases"},{"type":"ARTICLE","url":"https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467822"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2482734"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484099"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484207"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484377"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2484875"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489127"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2497452"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2497455"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2497464"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2497466"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500041"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500043"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500380"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50319.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-12383"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-12383"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12383"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-27145"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-27145"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27145"},{"type":"ARTICLE","url":"https://go.dev/cl/783621"},{"type":"ARTICLE","url":"https://go.dev/issue/79694"},{"type":"ARTICLE","url":"https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-5037"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33811"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-33811"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33811"},{"type":"ARTICLE","url":"https://go.dev/cl/767860"},{"type":"ARTICLE","url":"https://go.dev/issue/78803"},{"type":"ARTICLE","url":"https://groups.google.com/g/golang-announce/c/qcCIEXso47M"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-4981"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-34993"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-34993"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34993"},{"type":"ARTICLE","url":"https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00"},{"type":"ARTICLE","url":"https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-40898"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-40898"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40898"},{"type":"ARTICLE","url":"https://github.com/quic-go/quic-go/releases/tag/v0.59.1"},{"type":"ARTICLE","url":"https://github.com/quic-go/quic-go/security/advisories/GHSA-vvgj-x9jq-8cj9"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-44545"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-44545"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44545"},{"type":"ARTICLE","url":"https://github.com/django/daphne/blob/main/CHANGELOG.txt"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48526"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48526"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48526"},{"type":"ARTICLE","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-54059"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-54059"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54059"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-54060"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-54060"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54060"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-55379"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-55379"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55379"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-55380"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-55380"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55380"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-59197"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-59197"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59197"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/pull/9695"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"ARTICLE","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-59885"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-59885"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59885"},{"type":"ARTICLE","url":"https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9"},{"type":"ARTICLE","url":"https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4"},{"type":"ARTICLE","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-59886"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-59886"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59886"},{"type":"ARTICLE","url":"https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886"},{"type":"ARTICLE","url":"https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r"}],"affected":[{"package":{"name":"automation-eda-controller","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/automation-eda-controller"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-eda-controller-base","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/automation-eda-controller-base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-eda-controller-base-services","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/automation-eda-controller-base-services"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-eda-controller-event-stream-services","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/automation-eda-controller-event-stream-services"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-eda-controller-worker-services","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/automation-eda-controller-worker-services"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-eda-controller","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/automation-eda-controller"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-eda-controller-base","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/automation-eda-controller-base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-eda-controller-base-services","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/automation-eda-controller-base-services"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-eda-controller-event-stream-services","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/automation-eda-controller-event-stream-services"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-eda-controller-worker-services","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/automation-eda-controller-worker-services"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.21-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"receptor","ecosystem":"Red Hat:ansible_automation_platform_developer:2.5::el8","purl":"pkg:rpm/redhat/receptor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.6.7-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"receptor","ecosystem":"Red Hat:ansible_automation_platform_inside:2.5::el8","purl":"pkg:rpm/redhat/receptor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.6.7-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"receptor","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/receptor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.6.7-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"receptor","ecosystem":"Red Hat:ansible_automation_platform_developer:2.5::el9","purl":"pkg:rpm/redhat/receptor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.6.7-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"receptor","ecosystem":"Red Hat:ansible_automation_platform_inside:2.5::el9","purl":"pkg:rpm/redhat/receptor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.6.7-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"receptor","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/receptor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.6.7-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-gateway-proxy-server","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/automation-gateway-proxy-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.5.10-7.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-gateway-proxy-server","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/automation-gateway-proxy-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.6.17-2.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"python3.12-aiohttp","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/python3.12-aiohttp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.14.1-2.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"python3.12-aiohttp","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/python3.12-aiohttp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.14.1-2.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"python3.12-daphne","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/python3.12-daphne"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.2.2-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"python3.12-daphne","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/python3.12-daphne"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.2.2-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-controller-venv-tower","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/automation-controller-venv-tower"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.6.31-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"automation-controller-venv-tower","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/automation-controller-venv-tower"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.6.31-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"python3.12-pillow","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/python3.12-pillow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:12.3.0-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"python3.12-pillow","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/python3.12-pillow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:12.3.0-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"python3.12-pyasn1","ecosystem":"Red Hat:ansible_automation_platform:2.5::el8","purl":"pkg:rpm/redhat/python3.12-pyasn1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.6.4-1.el8ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}},{"package":{"name":"python3.12-pyasn1","ecosystem":"Red Hat:ansible_automation_platform:2.5::el9","purl":"pkg:rpm/redhat/python3.12-pyasn1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.6.4-1.el9ap"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:50319.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"}]}