Skip to content
Red HatCVE-2026-80179

Red Hat Ansible Automation Platform 2: resource exhaustion

Medium5.9CVE-2026-80179 · Published Aug 28, 2026 · updated Aug 31, 2026

A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Ansible Automation Platform 2
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat file-psd plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat libsolv: denial of service
Medium5.5Aug 28
Red Hat file-ico plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat file-pvr plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat GIMP: denial of service
Medium6.1Aug 28
Red Hat FFmpeg: denial of service
Medium5.4Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.