CVE-2025-9908 - CVE House
Back to Database
Status published Medium CVE-2025-9908

Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams

Vulnerability Description

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By exfiltrating these headers, an attacker could spoof trusted requests, escalate privileges, or perform malicious event injection.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9908

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This issue was discovered by Elijah DeLee (Red Hat).

Affected Vendor

Affected Software

Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.5, Red Hat Ansible Automation Platform 2.6
Vulnerable Versions:
0:3.1.1-1.el8ap, 0:25.12.0-1.el8ap, 0:25.12.2-1.1.el8ap, 0:0.1.4-1.el8ap, 0:1.1.14-1.el8ap, 0:4.10.10-1.el8ap, 0:2.13.0-1.el8ap, 0:0.4.0-1.el8ap, 0:4.2.26-1.el8ap, 0:2.1.2-1.el8ap, 0:0.4.36-2.el8ap, 0:23.0.0-1.el8ap, 0:1.6.0-1.el8ap, 0:9.0.1-1.el8ap, 0:3.8.0-1.el8ap, 0:0.2.15-1.el8ap, 0:0.4.2-1.el8ap, 0:25.12.0-1.2.el8ap, 0:4.15.0-1.el8ap, 0:3.1.1-1.el9ap, 0:25.12.0-1.el9ap, 0:25.12.2-1.1.el9ap, 0:0.1.4-1.el9ap, 0:1.1.14-1.el9ap, 0:4.10.10-1.el9ap, 0:2.13.0-1.el9ap, 0:0.4.0-1.el9ap, 0:4.2.26-1.el9ap, 0:2.1.2-1.el9ap, 0:0.4.36-2.el9ap, 0:23.0.0-1.el9ap, 0:1.6.0-1.el9ap, 0:9.0.1-1.el9ap, 0:3.8.0-1.el9ap, 0:0.2.15-1.el9ap, 0:0.4.2-1.el9ap, 0:25.12.0-1.2.el9ap, 0:4.15.0-1.el9ap, 0:1.2.1-1.el9ap, sha256:07673470fb62db8bec12ec20b2500228c0c6d5108916dd936d91e10610b783d1, sha256:142125ce7f176ce4d9755f3124714bbfd8e10a687378988761d5451bd135ca76

Timeline

Official Publish: February 27th, 2026
Last Modified: March 3rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)