CVE Tools

Red Hat Ansible Automation Platform 2.5 For Rhel 8

49 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Red Hat Ansible Automation Platform 2.5 For Rhel 8, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Ansible Automation Platform 2.5 For Rhel 8 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Ansible Automation Platform 2.5 For Rhel 8 CVEs per month
MonthCVEs
2024-101
2024-113
2024-120
2025-010
2025-020
2025-032
2025-040
2025-050
2025-062
2025-071
2025-081
2025-090
2025-100
2025-110
2025-120
2026-011
2026-023
2026-030
2026-040
2026-051
2026-063
2026-073
2026-084
2026-0923

Severity

How the 49 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical714%
  • High1633%
  • Medium2347%
  • Low36%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Ansible Automation Platform 2.5 For Rhel 8.

  1. CVE-2026-84724Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process6.6
  2. CVE-2026-84720Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via orm-traversal count-oracle6.5
  3. CVE-2026-84718Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust4.3
  4. CVE-2026-84717Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates5.3
  5. CVE-2026-84716Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames6.6
  6. CVE-2026-84712Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership5.3
  7. CVE-2026-84719Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane)9.9
  8. CVE-2026-84714Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment7.1
  9. CVE-2026-84706Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment7.6
  10. CVE-2026-75884Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups9.1
  11. CVE-2026-84691Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx error log setting discloses django secret_key and database credentials to an administrator8.7
  12. CVE-2026-84683Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout html view via ansi osc 8 hyperlink sequences (javascript: anchor) enabling session takeover8.7
  13. CVE-2026-84499Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via schedule/workflowjobtemplatenode survey min/max validation error message7.7
  14. CVE-2026-84502Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane pod9.9
  15. CVE-2026-84474Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match9.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store