Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-12383

CVE-2026-12383: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-12383] ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN

    CVE-2026-12383Source published Source updated

    A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentication without verifying that the header originated from a trusted proxy. Additionally, the expected certificate Distinguished Name is leaked in the 403 error response body. An attacker who can reach the EDA API endpoint with a spoofed Subject header can inject arbitrary events into mTLS-protected event streams, triggering downstream automation actions. This flaw is a defense-in-depth failure in EDA that becomes exploitable when combined with the gateway header-forwarding issue (tracked as a separate CVE). The DN leak in the error response…

    Affected products in this advisory
    • Red Hat Ansible Automation Platform 2.5 for RHEL 8
    • Red Hat Ansible Automation Platform 2.5 for RHEL 9
    • Red Hat Ansible Automation Platform 2.6 for RHEL 9
    • Red Hat Ansible Automation Platform 2.7
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • automation-eda-controller-0:1.1.21-1.el8ap
    • automation-eda-controller-0:1.1.21-1.el9ap
    • automation-eda-controller-0:1.2.11-1.el9ap
    • ansible-automation-platform-27/eda-controller-rhel9:1785374869

    3 more entries in the full advisory.

    Mitigation guidance
    • The following practices would help for avoiding exposure and mitigate this flaw: - Ensure the EDA server is not directly accessible from untrusted networks; all traffic should route through the AAP Gateway which should perform mTLS validation. - If possible, configure network-level access controls to restrict which source IPs can reach the EDA backend API. - Monitor EDA event streams for unexpected events_received counter changes. - Review and rotate mTLS client certificates if unauthorized access is suspected, as the expected DN may have been leaked via the 403 error response.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery