CVE-2025-9908: Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams

Published Sep 3, 2025
·
Updated

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-) and event stream URLs via crafted requests and job templates. By exfiltrating these headers, an attacker could spoof trusted requests, escalate privileges, or perform malicious event injection.

Other sources

A user can gain access to sensitive infrastructure headers and event stream url which has been characterized as sensitive (to avoid DDoS type attacks).

If there is an event stream set up by an administrator, and a credential to the controller to allow job template action (they could create that or have it shared with them), they can gain knowledge of other sensitive internal headers, including, but not limited to, X-Trusted-Proxy.

Red Hat

Affected Software

8 affected components
redhat/ansible-automation-platform
All of the following
Any of the following
redhat Ansible Automation Platform<2.6
redhat Ansible Developer=1.2
redhat Ansible Developer=1.3
redhat Ansible Inside=1.3
redhat Ansible Inside=1.4
Any of the following
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0

Event History

Sep 3, 2025
Data Sourced
via Red Hat·07:53 AM
DescriptionSeverityAffected Software
Feb 27, 2026
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-9908?

CVE-2025-9908 has been classified as a medium severity vulnerability due to the unauthorized access to sensitive internal headers.

2

How do I fix CVE-2025-9908?

To fix CVE-2025-9908, upgrade to a patched version of the Red Hat Ansible Automation Platform as indicated in the vendor's advisories.

3

Who is affected by CVE-2025-9908?

CVE-2025-9908 affects users of the Red Hat Ansible Automation Platform, specifically those using Event-Driven Ansible event streams.

4

What types of data are exposed in CVE-2025-9908?

CVE-2025-9908 exposes sensitive internal infrastructure headers which could lead to further exploitation or data leakage.

5

Is authentication required to exploit CVE-2025-9908?

Yes, CVE-2025-9908 requires authentication as it allows access to sensitive information for already authenticated users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203