CVE-2025-9908 Details
Description
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By exfiltrating these headers, an attacker could spoof trusted requests, escalate privileges, or perform malicious event injection.
A vulnerability exists in Red Hat Ansible Automation Platform's Event-Driven Ansible (EDA) Event Streams, allowing authenticated users to access sensitive internal infrastructure headers, such as X-Trusted-Proxy and X-Envoy-*, along with event stream URLs. This access is gained through crafted requests and job templates. The exfiltration of these headers could enable an attacker to spoof trusted requests, escalate privileges, or inject malicious events.
Users can upgrade to Red Hat Ansible Automation Platform 2.6 or 2.5, both of which include the necessary fix. Instructions for applying this update are available in the Red Hat Ansible Automation Platform documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:19201 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2025:19221 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2025:23069 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2025:23131 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2025-9908 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2392835 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat ansible automation platform | < 2.6 |
CPE
Remediation
| |
| redhat ansible developer | 1.2 1.3 |
CPE
Remediation
| |
| redhat ansible inside | 1.3 1.4 |
CPE
Remediation
| |
| redhat enterprise linux | 8.0 9.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | Initial Analysis | [email protected] |
| Feb 27, 2026 | New CVE Received | [email protected] |