[NEW] [high] Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Multiple vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Ansible Automation Platform to bypass security measures, conduct cross-site scripting attacks, manipulate data, trigger a denial-of-service condition, or execute arbitrary code.
CSIRTS triage
- What
- Multiple vulnerabilities can be exploited by a remote, anonymous attacker to bypass security measures, conduct cross-site scripting attacks, manipulate data, trigger denial-of-service conditions, or execute arbitrary code.
- Who is affected
- Deployments of Red Hat Ansible Automation Platform.
- Urgency
- Remediation is high urgency due to the potential for remote code execution and other severe impacts.
- Action
- Update to the latest version to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Ansible Automation Platform
Get an email when a new Ansible Automation Platform advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2452
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-598730.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
- Low exploitation riskCVE-2026-598740.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-488010.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-442890.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all scored CVEs.
- Low exploitation riskCVE-2026-442900.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-442910.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-442920.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-457400.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-131490.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-136760.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59873 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59874 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48801 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44289 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44290 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44291 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-44292 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-45740 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13149 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13676 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49978 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)cert-fr-avis
- medium[NEW] [medium] Red Hat OpenShift Container Platform (fast-uri, OpenTelemetry-Go): Multiple vulnerabilitiescert-bund
- highGHSA-4c8g-83qw-93j6: fast-uri vulnerable to host confusion via failed IDN canonicalizationghsa
- criticalGHSA-23hp-3jrh-7fpw: node-tar: Decompression/parse DoS via unlimited inputghsa
- highGHSA-8x88-c5mf-7j5w: node-tar: Negative tar entry size causes infinite loop in archive replaceghsa
- mediumCVE-2026-49978: DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4…nvd
- unknownCVE-2026-48801: linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt…nvd
- highCVE-2026-59873: node-tar: Decompression/parse DoS via unlimited inputmsrc
- highCVE-2026-59874: node-tar: Negative tar entry size causes infinite loop in archive replacemsrc
- highCVE-2026-59874: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accep…nvd
- highCVE-2026-59873: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not…nvd
- unknownCVE-2026-13149: brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibi…nvd
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31