Red Hat Ansible Automation Platform Sensitive Internal Headers Disclosure Vulnerability

Vulnerability

A vulnerability exists in Red Hat Ansible Automation Platform's Event-Driven Ansible (EDA) Event Streams, allowing authenticated users to access sensitive internal infrastructure headers, such as X-Trusted-Proxy and X-Envoy-*, along with event stream URLs. This access is gained through crafted requests and job templates. The exfiltration of these headers could enable an attacker to spoof trusted requests, escalate privileges, or inject malicious events.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive internal headers, allowing for privilege escalation, request spoofing, and malicious event injection.

Reproduction

To reproduce this vulnerability, an authenticated user with access to an EDA event stream and a job template can send an event that includes crafted requests. This will trigger the disclosure of sensitive internal headers and event stream URLs.

Remediation

Users can upgrade to Red Hat Ansible Automation Platform 2.6 or 2.5, both of which include the necessary fix. Instructions for applying this update are available in the Red Hat Ansible Automation Platform documentation.

Added: Feb 27, 2026, 8:21 AM
Updated: Feb 27, 2026, 2:27 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
0.6
exploitability
5.2
remediation
7.7
relevance
3.3
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.