live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
newsPLATFORM

AAP 2.7-8 closes critical GitPython and Vault paths across controller and hub

The September patch maps Git command-injection and Kubernetes token-exfiltration fixes to specific Ansible Automation Platform components and operator builds.

Compare controller and hub fixes across AAP 2.7-8.
Side by side: what changed
By The News Desk· Sep 20, 2026the quick take — two AI hosts go live when you do

Red Hat’s Ansible Automation Platform 2.7-8 update is not a single-library refresh. The September 14 release notes place the most consequential fixes in Automation Controller and Automation Hub, while a separate Vault credential fix lands in Controller.

What changed

The update ships Automation Controller 4.8.8, Automation Hub 4.12.6, Event-Driven Ansible 1.3.10 and Receptor 1.6.8. For OpenShift installations, Red Hat lists new namespace- and cluster-scoped AAP Operator builds under the 2.7.0 channel.

Controller and Hub both receive a broad GitPython repair set covering unsafe clone options, command injection, malicious Git templates, environment-variable exposure and arbitrary file operations. Controller moves to GitPython 3.1.59; Hub receives 3.1.57 or later. The release notes attach the remote-code and command-execution fixes to the controller-rhel9 and hub-rhel9 images rather than every AAP service.

Controller also fixes CVE-2026-12564 in the HashiCorp Vault credential plugin. Red Hat says the flaw could expose a Kubernetes service-account token through server-side request forgery. The corrected path obtains short-lived, audience-scoped credentials through Kubernetes’ TokenRequest API.

Who needs to act

Teams running Automation Controller or private Automation Hub should treat 2.7-8 as the upgrade target when project synchronization or other workflows consume Git URLs or options that are not fully controlled by administrators. Clusters using the Vault credential plugin have a second reason to prioritize Controller 4.8.8, because that component contains the token-exfiltration fix.

The operator update also creates runtime NetworkPolicy resources for Controller, Hub, Event-Driven Ansible, Lightspeed, the platform gateway, the resource operator and the metrics service. That is a useful containment change, but it does not replace the patched application images.

Upgrade check

Operators should verify that the resulting deployment reports Controller 4.8.8 and Hub 4.12.6, and that the installed AAP Operator build matches one of the two builds Red Hat lists for 2.7-8. Environments that use the containerized installer should move to bundle or online installer 2.7-8.

After the update, test source-control project synchronization and any Controller credentials backed by HashiCorp Vault. For OpenShift deployments, inspect the generated NetworkPolicy objects before assuming existing cross-namespace integrations will continue to reach AAP pods. The release contains many lower-severity dependency fixes, but the practical upgrade decision rests on whether Controller, Hub and the Vault credential path are present.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.