CVE-2026-71463: Red Hat Ansible Automation Platform 2.5 For Rhel 8

Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id > 100 %} conditional gating bypass both the AST check and the test-render (stub has small job.id). At runtime, the gated branch executes and exceptions write full tracebacks into notification body, which is POSTed to attacker-controlled webhook URL. Leaks install paths, Python version, source line numbers.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:4.6.33-1.el8ap (fixed in 0:4.6.33-1.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:4.6.33-1.el9ap (fixed in 0:4.6.33-1.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.6: before 1789673739 (fixed in 1789673739)
  • Red Hat Red Hat Ansible Automation Platform 2.6 For Rhel 9: before 0:4.7.17-1.el9ap (fixed in 0:4.7.17-1.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.7: before 1789580684 (fixed in 1789580684)

Published 2026-09-23. Last modified 2026-09-25.