CVE-2025-5988: Red Hat Ansible Automation Platform 2.5 For Rhel 8

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:2.5.20250730-2.el8ap (fixed in 0:2.5.20250730-2.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:2.5.20250730-2.el9ap (fixed in 0:2.5.20250730-2.el9ap)

Published 2025-08-04. Last modified 2026-06-17.