Red Hat released OpenShift Container Platform 4.13.55 to remediate two Important Jinja2 vulnerabilities, CVE-2024-56201 and CVE-2024-56326, through advisory RHSA-2025:1118. The vulnerabilities affect Jinja versions before 3.1.5 and can allow arbitrary Python code execution despite Jinja's sandbox protections in applications that render untrusted templates.
CVE-2024-56201 requires an attacker to control both template content and its filename, while CVE-2024-56326 requires a suitable application-defined filter that indirectly invokes a malicious string object's str.format method. Red Hat advised OpenShift 4.13 users to update affected packages and container images through their release channel across RHEL 8 and 9 deployments on x86_64, ppc64le, s390x, and aarch64; organizations should also restrict user-controlled template filenames to an approved set where applicable.

See affected versions and whether adversaries are exploiting it.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:1710 for OpenShift Container Platform 4.15.46, providing updated RPM packages that remediate the Jinja2 sandbox-breakout flaw CVE-2024-56326, as well as vulnerabilities in golang.org/x/crypto/ssh and golang.org/x/net/html. A separate RHSA-2025:1711 advisory provided container images, and users were advised to upgrade through their applicable release channel.
Red Hat issued RHSA-2025:1861 for openstack-ansible-core in Red Hat OpenStack Platform 17.1 (Wallaby) on RHEL 9.2. The update remediated Jinja sandbox-breakout flaws CVE-2024-56201 and CVE-2024-56326, along with ansible-core flaw CVE-2024-9902, which could permit unauthorized content reads or writes.
Red Hat issued RHSA-2025:1130 for OpenShift Container Platform 4.15.45, remediating Jinja2 sandbox-breakout flaws CVE-2024-56201 and CVE-2024-56326 in updated RHEL 8 and RHEL 9 packages. The advisory instructed OpenShift 4.15 users to upgrade packages and images through the appropriate release channel.
Red Hat issued RHSA-2025:0842 for OpenShift Container Platform 4.14.46, remediating Jinja2 sandbox-breakout vulnerabilities CVE-2024-56201 and CVE-2024-56326. The Important-severity update supplied python3-jinja2 3.0.1-6.el9.2 packages and updated release packages for supported RHEL 8 and RHEL 9 OpenShift deployments.
Red Hat issued RHSA-2025:0656 for OpenShift Container Platform 4.17.14, providing updated packages and container images for RHEL 8 and RHEL 9 that remediate Jinja2 sandbox-breakout flaws CVE-2024-56201 and CVE-2024-56326. The Important-severity advisory instructed OpenShift 4.17 users to upgrade through the appropriate release channel.
RHSA-2025:0753 fixed CVE-2024-56201 in the ansible-automation-platform/ee-minimal execution-environment images for both RHEL 8 and RHEL 9.
RHSA-2025:0721 remediated CVE-2024-56201 for automation-controller and python3x-jinja2 in Red Hat Ansible Automation Platform 2.4 for RHEL 8.
Red Hat issued RHSA-2025:0345, an Important advisory updating fence-agents to version 4.10.0-20.el9_0.20 for RHEL 9.0 Update Services for SAP Solutions and related High Availability and Resilient Storage offerings. The update remediated Jinja2 sandbox-breakout vulnerabilities CVE-2024-56201 and CVE-2024-56326 across supported x86_64, ppc64le, aarch64, and s390x systems.
Red Hat issued RHSA-2025:0335, an Important advisory updating fence-agents for RHEL 9.2 lifecycle and support variants. The update remediated Jinja2 sandbox-breakout vulnerabilities CVE-2024-56201 and CVE-2024-56326 across supported RHEL 9.2 architectures and relevant High Availability and Resilient Storage offerings.
Red Hat published its CVE entry for CVE-2024-56201, a Jinja2 compiler flaw that can bypass the sandbox and enable arbitrary Python code execution when an attacker controls both template content and filename.
Red Hat published RHSA-2025:1118 for OpenShift Container Platform 4.13.55, fixing both CVE-2024-56201 and CVE-2024-56326 in updated packages and container images. The advisory instructed users to upgrade through their applicable release channel.
RHSA-2025:1249 remediated CVE-2024-56201 in the Discovery server and Discovery UI components for RHEL 9.
RHSA-2025:0834 fixed python-jinja2 in Ironic content for Red Hat OpenShift Container Platform 4.12, addressing CVE-2024-56201.
RHSA-2025:1101 provided further fixes for CVE-2024-56201 in ansible-automation-platform/ee-minimal images for RHEL 8 and RHEL 9.
The Jinja project released version 3.1.5 to fix CVE-2024-56201, involving attacker-controlled template filenames, and CVE-2024-56326, involving indirect calls to a string object's format method. Both flaws could permit arbitrary Python code execution under their respective exploitation conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcedocs.openshift.com
Open sourcedocs.openshift.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.