#VU118710 Input validation error in Ansible Automation Platform - CVE-2025-9909
Published: November 24, 2025
Ansible Automation Platform
Red Hat Inc.
Description
The vulnerability allows a remote user to create hidden routes within the application.
The vulnerability exists due to insufficient validation of user-supplied input when creating routes. A remote privileged user can create routes starting with a double slash (//), that look very much like legitimate URLs. This can be used to set up a "honey-pot" route to capture and exfiltrate user credentials.