Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Ansible Automation Platform 2.5 for RHEL 8 — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Red Hat Ansible Automation Platform 2.5 for RHEL 8, with AI-generated Chinese analysis, references, and POCs.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-12383 Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn CWE-345 7.5 High2026-07-27
CVE-2026-12701 Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport CWE-22 9.0 Critical2026-07-20
CVE-2026-12382 Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing CWE-290 8.2 High2026-07-15
CVE-2026-11807 Eda-server: websocket missing authorization allows credential theft via activation_id spoofing CWE-862 9.6 Critical2026-06-23
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution CWE-88 7.8 High2026-06-05
CVE-2026-6266 Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified email linking CWE-305 8.3 High2026-05-04
CVE-2025-9909 Aap-gateway: improper path validation in gateway allows credential exfiltration CWE-647 6.7 Medium2026-02-27
CVE-2025-9908 Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams CWE-200 6.7 Medium2026-02-27
CVE-2025-9907 Event-driven-ansible: event stream test mode exposes sensitive headers in aap eda CWE-200 6.7 Medium2026-02-27
CVE-2025-14025 Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions CWE-279 8.5 High2026-01-08
CVE-2025-49520 Event-driven-ansible: authenticated argument injection in git url in eda project creation CWE-88 8.8 High2025-06-30
CVE-2025-49521 Event-driven-ansible: template injection via git branch and refspec in eda projects CWE-94 8.8 High2025-06-30

All 12 known CVE vulnerabilities affecting Red Hat Ansible Automation Platform 2.5 for RHEL 8 with full Chinese analysis, references, and POCs where available.