Ansible Automation Platform patch release October 28, 2025
The following release notes detail the updates for the Ansible Automation Platform patch released on October 28, 2025.
This release includes the following components and versions:
| Release Date | Component versions |
|---|---|
| October 28, 2025 |
|
CSV Versions in this release:
- Namespace: aap-operator.v2.6.0-0.1762261205
- Cluster: aap-operator.v2.6.0-0.1762261209
CVE Copy linkLink copied!
With this update, the following CVEs have been addressed:
CVE-2025-59682python-django: Potential partial directory-traversal via archive.extract().(AAP-54755)
CVE-2025-9908event-driven-ansible: Sensitive internal headers disclosure in Ansible Automation Platform Event-Driven Ansible event streams.(AAP-53582)
CVE-2025-9907event-driven-ansible: Event stream test mode exposes sensitive headers in Ansible Automation Platform Event-Driven Ansible.(AAP-53580)
CVE-2025-59343automation-platform-ui: tar-fs symlink validation bypass.(AAP-54392)
CVE-2025-58754automation-platform-ui: Axios DoS via lack of data size check.(AAP-53718)
Ansible Automation Platform Copy linkLink copied!
- Features
-
- Added a step in the subscription wizard that allows the user to configure automation analytics.(AAP-55094)
- Added two new toggle options on the subscription wizard to allow for fetching subscriptions using basic authentication.(AAP-47865)
- Bug Fixes
-
- Fixed an issue where the
ansible-builderandansible-navigatordid not use execution environment images from ansible-automation-platform-26 namespace by default.(AAP-54934) - Fixed an issue where the settings did not display Red Hat consistently in the API and UI.(AAP-54276)
- Fixed an issue where the decision environment dropdown was broken. Replaced the dropdown type for decision environments in the rulebook activation form so that when there are no decision environments available, the dropdown displays No results found instead of an empty dropdown.(AAP-53844)
- Fixed an issue where creating resources with
cookie/xcrftoken failed. Aligned dependency versions between Konflux build and component repository.(AAP-53561) - Fixed an issue where the component label for the Platform Auditor role did not display all components.(AAP-53551)
- Fixed an issue where empty strings were displayed in the extra variables field on the Jobs > Details page.(AAP-49448)
- Fixed an issue where the Load More in authentication mapping role dropdown did not work.(AAP-54049) HubName
- Fixed an issue where the user was unable to create Event-Driven Ansible or automation hub roles when creating a custom role and selecting the Automation Decisions project or credential types because the UI displayed only the automation controller permissions.(AAP-54756) ControllerName
- Fixed an issue where the PatternFly 6 Upgrade broke the Ansible Automation Platform topology layout and fullscreen mode.(AAP-51106)
- Fixed an issue where some fields were missing
autocomplete = new-passwordsetting.(AAP-55783) - Fixed an issue where the user was unable to select the default execution environment in the automation settings page.(AAP-39321)
- Fixed an issue where the LDAP Group Type parameters failed to save user preferences when the language was initially set to
es_ES, resulting in a wrong version displayed on the user interface due to an uninitialized translation object.(AAP-56356) - Fixed an issue that prevented SAML and AzureAD authentication when local user accounts share the same email address.(AAP-56518)
- Fixed an issue where the
- Deprecated
-
- Subscription credentials can no longer be viewed/edited from the system settings page.(AAP-55014)
Ansible Automation Platform Operator Copy linkLink copied!
- Bug Fixes
-
- Fixed an issue where the Ansible Lightspeed API version did not work during Ansible Automation Platform idle.(AAP-54174)
- Fixed an issue that caused a failure to gather the job data from the controller API.(AAP-55632)
- Fixed a bug where the user could set an image without the respective version, causing the installation to enter an error loop.(AAP-55642)
- Fixed an issue where the backup and restore Ansible Automation Platform instance failed, from cluster A to cluster B, when restoring an upgraded AAP environment from 2.4.(AAP-55648)
Red Hat Ansible Lightspeed Copy linkLink copied!
- Features
- Ability to deploy Red Hat Ansible Lightspeed on new containerized installations of Ansible Automation Platform 2.6
You can deploy and use Red Hat Ansible Lightspeed when you install or upgrade to a containerized installation of Ansible Automation Platform 2.6.
Red Hat Ansible Lightspeed includes two main components that enhance your automation experience with generative artificial intelligence (AI):
Ansible Lightspeed intelligent assistant, which is an AI-powered, intuitive chat interface embedded within the Ansible Automation Platform.
The integration of Red Hat Ansible Lightspeed intelligent assistant with the Model Context Protocol (MCP) server is available as a Technology Preview release. This integration enhances the user experience by delivering relevant, dynamically sourced data results to your queries.
Technology Preview features are not supported with Red Hat production service level agreements (SLAs) and might not be functionally complete. Red Hat does not recommend using them in production. These features provide early access to upcoming product features, enabling customers to test functionality and provide feedback during the development process. For more information about the support scope of Red Hat Technology Preview features, see Technology Preview Features Support Scope.
Ansible Lightspeed coding assistant, which is a generative AI service that works with IBM watsonx Code Assistant to help developers create and maintain Ansible content more efficiently.
For more information, see Deploy Red Hat Ansible Lightspeed on containerized Ansible Automation Platform.
- Enhancements
-
- Added
postgres_extra_settingsto Ansible Automation Platform operators to apply PostgreSQL configuration file level changes to managed postgres.(AAP-55053)
- Added
Automation controller Copy linkLink copied!
- Enhancements
-
- Added support for Red Hat username and password for the subscription management API.(AAP-54975)
- Bug Fixes
-
- Fixes the
system_administratorrole creation race condition which most commonly happened on new Openshift deployments resulting in the default instance group not being created.(AAP-54963) - Fixed an issue where the Controller container file was missing the metrics utility in version 2.6.(AAP-54948)
- Fixed an issue where the
awx.awx.licenseappeared to succeed when given an invalid pool/subscription.(AAP-54768) - Fixed an issue where the
ansible.platformcollection did not work with the default Red Hat Ansible Automation Platform credential type.(AAP-41000) - Fixed an issue where there was a duplicate value (
subsystem_metrics_pipe_execute_seconds) detected under api/controller/v2/metrics/ on Ansible Automation Platform 2.5.(AAP-55621) - Fixed an issue where the platform auditor did not have access to controller settings.(AAP-55607)
- Fixes the
Automation hub Copy linkLink copied!
- Enhancements
-
- Fixed an HTTP 500 error when getting /api/galaxy/_ui/v2/users/3/.(AAP-54260)
- Bug Fixes
-
- Fixed an HTTP 500 error when getting /api/galaxy/_ui/v2/users/3/.(AAP-54260)
Container-based Ansible Automation Platform Copy linkLink copied!
- Enhancements
-
- Implemented preflight ansible-core version validation.(AAP-54932)
- Bug Fixes
-
- Fixed an issue where
REDHAT_CANDLEPIN_VERIFYwas not being used for the correct CA permissions so that the controller could not make requests to subscription.rhsm.redhat.com.(AAP-55180)
- Fixed an issue where
RPM-based Ansible Automation Platform Copy linkLink copied!
- Bug Fixes
-
- Fixed an issue where setting
automationgateway_disable_https=falseresulted in install failure.(AAP-55466) - Fixed an issue where
RESOURCE_KEY SECRET_KEYwas not updated when restoring from a different environment.(AAP-54942) - Fixed an issue where Event-Driven Ansible DE credentials failed to populate on initial installation.(AAP-54519)
- Fixed an issue where setting
Fixed an issue where the envoy.log for automation gateway did not receive logs after it was rotated.(AAP-51779)
Fixed an issue where REDHAT_CANDLEPIN_VERIFY was not being used for the correct CA permissions so that the controller could not make requests to subscription.rhsm.redhat.com.(AAP-55183)
Event-Driven Ansible Copy linkLink copied!
- Features
-
- Changes in the deployment and nginx configuration now allow for gunicorn and daphne to bind to
::as well, essentially allowing for seamlessly binding to IPv4 and IPv6 (dual-stack) addresses, while also enabling the operator to run in single-stack IPv6 or IPv4 scenarios.(AAP-56192)
- Changes in the deployment and nginx configuration now allow for gunicorn and daphne to bind to
Receptor Copy linkLink copied!
- Bug Fixes
- Fixed an issue where there was stability issue on long-running jobs, clusters under heavy load, and network flakiness.(AAP-53742)