CVE-2025-9907 - CVE House
Back to Database
Status published Medium CVE-2025-9907

Event-driven-ansible: event stream test mode exposes sensitive headers in aap eda

Vulnerability Description

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9907

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This issue was discovered by Elijah DeLee (Red Hat).

Affected Vendor

Affected Software

Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.5, Red Hat Ansible Automation Platform 2.6
Vulnerable Versions:
0:3.1.1-1.el8ap, 0:25.12.0-1.el8ap, 0:25.12.2-1.1.el8ap, 0:0.1.4-1.el8ap, 0:1.1.14-1.el8ap, 0:4.10.10-1.el8ap, 0:2.13.0-1.el8ap, 0:0.4.0-1.el8ap, 0:4.2.26-1.el8ap, 0:2.1.2-1.el8ap, 0:0.4.36-2.el8ap, 0:23.0.0-1.el8ap, 0:1.6.0-1.el8ap, 0:9.0.1-1.el8ap, 0:3.8.0-1.el8ap, 0:0.2.15-1.el8ap, 0:0.4.2-1.el8ap, 0:25.12.0-1.2.el8ap, 0:4.15.0-1.el8ap, 0:3.1.1-1.el9ap, 0:25.12.0-1.el9ap, 0:25.12.2-1.1.el9ap, 0:0.1.4-1.el9ap, 0:1.1.14-1.el9ap, 0:4.10.10-1.el9ap, 0:2.13.0-1.el9ap, 0:0.4.0-1.el9ap, 0:4.2.26-1.el9ap, 0:2.1.2-1.el9ap, 0:0.4.36-2.el9ap, 0:23.0.0-1.el9ap, 0:1.6.0-1.el9ap, 0:9.0.1-1.el9ap, 0:3.8.0-1.el9ap, 0:0.2.15-1.el9ap, 0:0.4.2-1.el9ap, 0:25.12.0-1.2.el9ap, 0:4.15.0-1.el9ap, 0:1.2.1-1.el9ap, sha256:07673470fb62db8bec12ec20b2500228c0c6d5108916dd936d91e10610b783d1, sha256:142125ce7f176ce4d9755f3124714bbfd8e10a687378988761d5451bd135ca76

Timeline

Official Publish: February 27th, 2026
Last Modified: February 28th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)