Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
RHSA-2026:3958
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:3958
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:3958.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:3958
Upstream
CVE-2025-13465
CVE-2025-14550
CVE-2025-59057
CVE-2025-61726
CVE-2025-69223
CVE-2026-0994
CVE-2026-1207
CVE-2026-1285
CVE-2026-1287
CVE-2026-1312
CVE-2026-21884
CVE-2026-22029
CVE-2026-23490
CVE-2026-24049
Related
GO-2026-4341
Published
2026-03-07T10:11:38Z
Modified
2026-03-07T10:30:49.315843Z
Severity
8.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update
Details
References
https://access.redhat.com/errata/RHSA-2026:3958
https://access.redhat.com/security/updates/classification/#important
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/html/release_notes/patch_releases
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade
https://bugzilla.redhat.com/show_bug.cgi?id=2427456
https://bugzilla.redhat.com/show_bug.cgi?id=2428412
https://bugzilla.redhat.com/show_bug.cgi?id=2428421
https://bugzilla.redhat.com/show_bug.cgi?id=2428426
https://bugzilla.redhat.com/show_bug.cgi?id=2430472
https://bugzilla.redhat.com/show_bug.cgi?id=2431740
https://bugzilla.redhat.com/show_bug.cgi?id=2431959
https://bugzilla.redhat.com/show_bug.cgi?id=2432398
https://bugzilla.redhat.com/show_bug.cgi?id=2434432
https://bugzilla.redhat.com/show_bug.cgi?id=2436338
https://bugzilla.redhat.com/show_bug.cgi?id=2436339
https://bugzilla.redhat.com/show_bug.cgi?id=2436340
https://bugzilla.redhat.com/show_bug.cgi?id=2436341
https://bugzilla.redhat.com/show_bug.cgi?id=2436342
https://issues.redhat.com/browse/AAP-62864
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3958.json
https://access.redhat.com/security/cve/CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
https://nvd.nist.gov/vuln/detail/CVE-2025-13465
https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg
https://access.redhat.com/security/cve/CVE-2025-14550
https://www.cve.org/CVERecord?id=CVE-2025-14550
https://nvd.nist.gov/vuln/detail/CVE-2025-14550
https://docs.djangoproject.com/en/dev/releases/security/
https://groups.google.com/g/django-announce
https://www.djangoproject.com/weblog/2026/feb/03/security-releases/
https://access.redhat.com/security/cve/CVE-2025-59057
https://www.cve.org/CVERecord?id=CVE-2025-59057
https://nvd.nist.gov/vuln/detail/CVE-2025-59057
https://github.com/remix-run/react-router/security/advisories/GHSA-3cgp-3xvw-98x8
https://access.redhat.com/security/cve/CVE-2025-61726
https://www.cve.org/CVERecord?id=CVE-2025-61726
https://nvd.nist.gov/vuln/detail/CVE-2025-61726
https://go.dev/cl/736712
https://go.dev/issue/77101
https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
https://pkg.go.dev/vuln/GO-2026-4341
https://access.redhat.com/security/cve/CVE-2025-69223
https://www.cve.org/CVERecord?id=CVE-2025-69223
https://nvd.nist.gov/vuln/detail/CVE-2025-69223
https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6mq8-rvhq-8wgg
https://access.redhat.com/security/cve/CVE-2026-0994
https://www.cve.org/CVERecord?id=CVE-2026-0994
https://nvd.nist.gov/vuln/detail/CVE-2026-0994
https://github.com/protocolbuffers/protobuf/pull/25239
https://access.redhat.com/security/cve/CVE-2026-1207
https://www.cve.org/CVERecord?id=CVE-2026-1207
https://nvd.nist.gov/vuln/detail/CVE-2026-1207
https://access.redhat.com/security/cve/CVE-2026-1285
https://www.cve.org/CVERecord?id=CVE-2026-1285
https://nvd.nist.gov/vuln/detail/CVE-2026-1285
https://access.redhat.com/security/cve/CVE-2026-1287
https://www.cve.org/CVERecord?id=CVE-2026-1287
https://nvd.nist.gov/vuln/detail/CVE-2026-1287
https://access.redhat.com/security/cve/CVE-2026-1312
https://www.cve.org/CVERecord?id=CVE-2026-1312
https://nvd.nist.gov/vuln/detail/CVE-2026-1312
https://access.redhat.com/security/cve/CVE-2026-21884
https://www.cve.org/CVERecord?id=CVE-2026-21884
https://nvd.nist.gov/vuln/detail/CVE-2026-21884
https://github.com/remix-run/react-router/security/advisories/GHSA-8v8x-cx79-35w7
https://access.redhat.com/security/cve/CVE-2026-22029
https://www.cve.org/CVERecord?id=CVE-2026-22029
https://nvd.nist.gov/vuln/detail/CVE-2026-22029
https://github.com/remix-run/react-router/security/advisories/GHSA-2w69-qvjg-hvjx
https://access.redhat.com/security/cve/CVE-2026-23490
https://www.cve.org/CVERecord?id=CVE-2026-23490
https://nvd.nist.gov/vuln/detail/CVE-2026-23490
https://github.com/pyasn1/pyasn1/commit/3908f144229eed4df24bd569d16e5991ace44970
https://github.com/pyasn1/pyasn1/releases/tag/v0.6.2
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-63vm-454h-vhhq
https://access.redhat.com/security/cve/CVE-2026-24049
https://www.cve.org/CVERecord?id=CVE-2026-24049
https://nvd.nist.gov/vuln/detail/CVE-2026-24049
https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef
https://github.com/pypa/wheel/releases/tag/0.46.2
https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx
Affected packages
Red Hat:ansible_automation_platform:2.6::el10
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el10ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor-debuginfo
Package
Name
receptor-debuginfo
Purl
pkg:rpm/redhat/receptor-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el10ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor-debugsource
Package
Name
receptor-debugsource
Purl
pkg:rpm/redhat/receptor-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el10ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el10ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
Red Hat:ansible_automation_platform:2.6::el9
automation-platform-ui
Package
Name
automation-platform-ui
Purl
pkg:rpm/redhat/automation-platform-ui
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.6.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
python3.12-django
Package
Name
python3.12-django
Purl
pkg:rpm/redhat/python3.12-django
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.2.28-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor-debuginfo
Package
Name
receptor-debuginfo
Purl
pkg:rpm/redhat/receptor-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor-debugsource
Package
Name
receptor-debugsource
Purl
pkg:rpm/redhat/receptor-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
python3.12-aiohttp
Package
Name
python3.12-aiohttp
Purl
pkg:rpm/redhat/python3.12-aiohttp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.13.3-2.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
python3.12-aiohttp-debuginfo
Package
Name
python3.12-aiohttp-debuginfo
Purl
pkg:rpm/redhat/python3.12-aiohttp-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.13.3-2.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
python3.12-aiohttp-debugsource
Package
Name
python3.12-aiohttp-debugsource
Purl
pkg:rpm/redhat/python3.12-aiohttp-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.13.3-2.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
python3.12-protobuf
Package
Name
python3.12-protobuf
Purl
pkg:rpm/redhat/python3.12-protobuf
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.29.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
python3.12-protobuf-debuginfo
Package
Name
python3.12-protobuf-debuginfo
Purl
pkg:rpm/redhat/python3.12-protobuf-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.29.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
python3.12-protobuf-debugsource
Package
Name
python3.12-protobuf-debugsource
Purl
pkg:rpm/redhat/python3.12-protobuf-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.29.6-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller
Package
Name
automation-controller
Purl
pkg:rpm/redhat/automation-controller
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller-cli
Package
Name
automation-controller-cli
Purl
pkg:rpm/redhat/automation-controller-cli
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller-server
Package
Name
automation-controller-server
Purl
pkg:rpm/redhat/automation-controller-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller-ui
Package
Name
automation-controller-ui
Purl
pkg:rpm/redhat/automation-controller-ui
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
Red Hat:ansible_automation_platform_developer:2.6::el9
python3.12-django
Package
Name
python3.12-django
Purl
pkg:rpm/redhat/python3.12-django
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.2.28-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor-debuginfo
Package
Name
receptor-debuginfo
Purl
pkg:rpm/redhat/receptor-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor-debugsource
Package
Name
receptor-debugsource
Purl
pkg:rpm/redhat/receptor-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller
Package
Name
automation-controller
Purl
pkg:rpm/redhat/automation-controller
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller-cli
Package
Name
automation-controller-cli
Purl
pkg:rpm/redhat/automation-controller-cli
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller-server
Package
Name
automation-controller-server
Purl
pkg:rpm/redhat/automation-controller-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller-ui
Package
Name
automation-controller-ui
Purl
pkg:rpm/redhat/automation-controller-ui
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.7.9-1.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
Red Hat:ansible_automation_platform_inside:2.6::el9
receptor
Package
Name
receptor
Purl
pkg:rpm/redhat/receptor
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor-debuginfo
Package
Name
receptor-debuginfo
Purl
pkg:rpm/redhat/receptor-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptor-debugsource
Package
Name
receptor-debugsource
Purl
pkg:rpm/redhat/receptor-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
receptorctl
Package
Name
receptorctl
Purl
pkg:rpm/redhat/receptorctl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.6.3-4.el9ap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3958.json"
RHSA-2026:3958 - OSV