Red Hat released multiple Important security advisories for rhc-worker-playbook on Red Hat Enterprise Linux 10, updating the yggdrasil worker that receives Ansible playbooks and executes them on the local host. The fixes were issued across RHEL 10.0, 10.1, and 10.2 channels and covered several architectures, including x86_64, aarch64, ppc64le, and s390x. Early updates shipped rhc-worker-playbook version 0.2.3-4 for RHEL 10.0 and 10.1 to remediate CVE-2026-27137 in Go's crypto/x509, involving incorrect email constraint enforcement, and CVE-2026-25679 in Go's net/url, involving incorrect parsing of IPv6 host literals.
A subsequent advisory updated rhc-worker-playbook to version 0.2.3-5.el10_1 to fix CVE-2026-32282, where Go's Root.Chmod could follow symlinks outside the intended root, and CVE-2026-32283, a denial-of-service condition in Go crypto/tls triggered by repeated TLS 1.3 key update messages. Red Hat later rolled these fixes into rhc-worker-playbook-0.2.7-3.el10_2 for RHEL 10.2 and also addressed CVE-2025-61726, a memory exhaustion issue, consolidating five Go-component vulnerabilities in the latest package set.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-19, Red Hat published Important advisory RHSA-2026:19132 for rhc-worker-playbook on Red Hat Enterprise Linux 10. The update to version 0.2.7-3.el10_2 fixes five vulnerabilities: CVE-2025-61726, CVE-2026-27137, CVE-2026-25679, CVE-2026-32282, and CVE-2026-32283.
On 2026-04-29, Red Hat published Important advisory RHSA-2026:11863 for rhc-worker-playbook on Red Hat Enterprise Linux 10. The update to version 0.2.3-5.el10_1 addresses CVE-2026-32282 and CVE-2026-32283.
On 2026-04-27, Red Hat published Important advisory RHSA-2026:10929 for rhc-worker-playbook on Red Hat Enterprise Linux 10.0 support channels. The update to version 0.2.3-4.el10_0 fixes the same two vulnerabilities, CVE-2026-27137 and CVE-2026-25679, for multiple architectures.
On 2026-04-23, Red Hat published Important advisory RHSA-2026:10169 for rhc-worker-playbook on Red Hat Enterprise Linux 10. The update to version 0.2.3-4.el10_1 fixes CVE-2026-27137 and CVE-2026-25679.
On 2026-03-09, Red Hat published Important advisory RHSA-2026:3971 for rhc-worker-playbook on Red Hat Enterprise Linux 10. The update to version 0.2.3-3.el10_1 fixes CVE-2025-61729, CVE-2025-61726, and CVE-2025-68121 across multiple architectures and support channels.
On 2026-03-09, Red Hat published Important advisory RHSA-2026:3970 for rhc-worker-playbook on Red Hat Enterprise Linux 10.0 support channels. The update to version 0.2.3-3.el10_0 fixes CVE-2025-61729, CVE-2025-61726, and CVE-2025-68121 across multiple architectures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.