CVE-2025-9907: Red Hat Ansible Automation Platform

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.

Affected products

  • Red Hat Ansible Automation Platform: before 2.6 (fixed in 2.6)
  • Red Hat Ansible Developer: version 1.2 only; version 1.3 only
  • Red Hat Ansible Inside: version 1.3 only; version 1.4 only

Published 2026-02-27. Last modified 2026-06-17.