Red Hat released an Important security update for Red Hat Ansible Automation Platform 2.4 to fix CVE-2025-61726, a memory exhaustion flaw in Go's net/url query-parameter parsing that affects the platform's Receptor component. The advisory applies across multiple Ansible Automation Platform, Ansible Inside, and Ansible Developer builds for RHEL 8 and RHEL 9 on x86_64, s390x, ppc64le, and aarch64, and requires customers to use the latest installer because older installers may fail during installation or upgrade.
Red Hat's 2.4 asynchronous release notes place the Receptor fix within a broader stream of security and stability updates spanning Automation controller, Automation hub, Event-Driven Ansible, the AAP Operator, and Red Hat Ansible Lightspeed. Those updates address additional risks including denial-of-service, SQL injection, XSS, request smuggling, sandbox breakout, arbitrary code execution, and information exposure, while also documenting platform changes such as a refresh to Python 3.12, PostgreSQL 15 adoption, newer OpenShift support, and fixes for inventory sync performance, long-running query failures, rendering crashes, and backup and restore issues.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
On August 4, 2026, Red Hat released Ansible Automation Platform 2.4 updates including Automation controller 4.5.35, Automation hub 4.9.8, Event-Driven Ansible 1.0.11, and Receptor 1.6.4. The release fixed an Automation hub UI crash caused by large API response fields and resolved job and workflow failures after long-running queries.
On July 15, 2026, Red Hat released an Ansible Automation Platform 2.4 update that fixed excessive inventory synchronization time when processing a large number of changes.
On May 4, 2026, Red Hat released Ansible Automation Platform 2.4 security and bug-fix updates across multiple components. The release added PQC signature support for execution environments in Automation hub and fixed an upgrade failure during Automation hub database migrations from older pulp_ansible versions.
On March 26, 2026, Red Hat released an Ansible Automation Platform 2.4 update that upgraded the platform to Python 3.12 and required a new installer for both containerized and RPM deployments. The release also noted that Django 5.2 requires PostgreSQL 14 or higher because PostgreSQL 13 support was dropped.
On February 25, 2026, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2025-61726, a memory exhaustion vulnerability in Go net/url query parameter parsing affecting Receptor.
On January 28, 2026, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2025-66471 in urllib3, CVE-2025-69223 in AIOHTTP, CVE-2025-64460 in Django XML deserialization, and CVE-2025-61729 in Receptor.
On January 6, 2026, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2025-68664 in Red Hat Ansible Lightspeed, described as arbitrary code execution via LangChain serialization injection.
On December 10, 2025, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2025-64459, a Django SQL injection issue in Red Hat Ansible Lightspeed.
On November 19, 2025, Red Hat updated Ansible Automation Platform 2.4 to require minimum supported RHEL versions 8.10 and 9.4. The same release updated nginx to 1.24, moved the platform from Python 3.9 to Python 3.11, and fixed CVE-2025-59530 in Receptor.
On September 22, 2025, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2025-57833, a Django SQL injection issue involving FilteredRelation column aliases.
On July 2, 2025, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2025-2287 in Receptor, described as request smuggling due to acceptance of invalid chunked data in Go net/http. The release also adopted PostgreSQL 15 for fresh installs and added upgrade logic for managed database deployments.
On June 9, 2025, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2025-26699, a potential denial-of-service issue in django.utils.text.wrap(). The same release also fixed unauthenticated execution environment pulls.
On April 9, 2025, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2025-2877 in ansible-rulebook, which exposed inventory passwords in plain text when starting a rulebook activation with debug verbosity in Event-Driven Ansible.
On March 26, 2025, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2025-27516, a Jinja sandbox breakout through the attr filter selecting the format method. The issue affected automation-controller, Jinja2 packages, and the ansible-lightspeed-container.
On January 29, 2025, Red Hat released an Ansible Automation Platform 2.4 update addressing CVE-2024-53908, a potential SQL injection issue in Django HasKey(lhs, rhs) on Oracle affecting automation-controller and Lightspeed.
On December 3, 2024, Red Hat released an Ansible Automation Platform 2.4 update that addressed CVE-2024-45801, an XSS vulnerability via prototype pollution in automation-controller.
On March 12, 2026, Red Hat issued Important security advisory RHSA-2026:4460 for Red Hat Ansible Automation Platform 2.4. The advisory provided an update for CVE-2025-61726 in Receptor and warned users to download the latest installer because older installers could fail during installation or upgrade.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
docs.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.