Red Hat released Important security updates for Ansible Automation Platform (AAP) 2.4 and 2.5 and its Execution Environments, remediating Jinja2 sandbox-breakout flaws CVE-2024-56201 and CVE-2024-56326, plus aiohttp request smuggling vulnerability CVE-2024-52304. The Jinja issues can be triggered through malicious filenames or indirect references to the format method, while the aiohttp flaw affects the pure-Python HTTP parser's handling of newlines in chunk extensions and may permit proxy or firewall bypasses when C extensions are unavailable or disabled.
The advisories also address Django denial-of-service issues CVE-2024-53907 and CVE-2024-56374, Django Oracle SQL injection CVE-2024-53908, and a gRPC-C++ denial-of-service condition in affected container releases. Organizations running AAP on RHEL 8 or 9—including ansible-lightspeed-container, Automation Controller, and ee-minimal-container images—should apply the updated packages and container images; updates include Automation Controller 4.5.17 or 4.6.7, Jinja2 3.1.5, Django 4.2.18, and aiohttp fixes.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2025:1101 for Ansible Automation Platform Execution Environments, addressing aiohttp request smuggling and two Jinja sandbox-breakout vulnerabilities in ee-minimal-container. Updated ansible-builder and ee-minimal images were published for RHEL 8 and 9.
Red Hat issued Important advisory RHSA-2025:0753 for Ansible Automation Platform Execution Environments, fixing aiohttp request smuggling and two Jinja sandbox-breakout flaws in ee-minimal-container. Updated ansible-builder and ee-minimal images were supplied for RHEL 8 and 9 supported architectures.
Red Hat issued Important advisory RHSA-2025:0341 for Ansible Automation Platform 2.5 container releases, addressing Jinja sandbox-breakout flaws, aiohttp request smuggling, and a gRPC-C++ denial-of-service issue. The update also updated the ansible.controller collection to version 4.6.6.
Red Hat released Important advisory RHSA-2025:0777 for Ansible Automation Platform 2.5, remediating Jinja sandbox-breakout and Django denial-of-service vulnerabilities. The update included automation-controller 4.6.7, python3.11-jinja2 3.1.5, and python3.11-django 4.2.18.
Red Hat issued Important advisory RHSA-2025:0722 for Ansible Automation Platform 2.4 container releases, addressing gRPC-C++, Django, Jinja2, and aiohttp vulnerabilities. The release updated Automation Controller and ansible.controller to version 4.5.17 and Ansible Lightspeed to 2.4.20250121.
Red Hat released Important advisory RHSA-2025:0721 for Ansible Automation Platform 2.4, fixing two Jinja sandbox-breakout vulnerabilities and Django Oracle SQL-injection flaw CVE-2024-53908. Automation Controller was updated to 4.5.17 and Jinja2 packages to 3.1.5.
Red Hat addressed CVE-2024-52304 in Ansible Automation Platform 2.5 for RHEL 8 and 9 through RHSA-2025:0340.
Red Hat addressed CVE-2024-52304 for Red Hat Satellite 6.16 on RHEL 8 and 9 through RHSA-2024:11574.
Red Hat addressed CVE-2024-52304, an aiohttp request-smuggling vulnerability, for Ansible Automation Platform 2.5 on RHEL 8 and 9 through RHSA-2024:10766.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.