cve-2026-53878
LOW CVSS 3.7 csaf_redhat
Description
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
Timeline
- Published
- 2026-07-07 14:00 UTC
- Last Modified
- 2026-07-10
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"document": {
"aggregate_severity": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"text": "Low"
},
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright © Red Hat, Inc. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "legal_disclaimer",
"text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
"title": "Terms of Use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://access.redhat.com/security/team/contact/",
"issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
"name": "Red Hat Product Security",
"namespace": "https://www.redhat.com"
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53878.json"
}
],
"title": "django: Django: HTTP header injection via DomainNameValidator accepting newlines",
"tracking": {
"current_release_date": "2026-07-10T14:25:02+00:00",
"generator": {
"date": "2026-07-10T14:25:02+00:00",
"engine": {
"name": "Red Hat SDEngine",
"version": "5.3.2"
}
},
"id": "CVE-2026-53878",
"initial_release_date": "2026-07-07T14:00:00+00:00",
"revision_history": [
{
"date": "2026-07-07T14:00:00+00:00",
"number": "1",
"summary": "Initial version"
},
{
"date": "2026-07-10T14:23:54+00:00",
"number": "2",
"summary": "Current version"
},
{
"date": "2026-07-10T14:25:02+00:00",
"number": "3",
"summary": "Last generated version"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Ansible Automation Platform 2",
"product": {
"name": "Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:ansible_automation_platform:2"
}
}
}
],
"category": "product_family",
"name": "Red Hat Ansible Automation Platform 2"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Discovery 2",
"product": {
"name": "Red Hat Discovery 2",
"product_id": "red_hat_discovery_2",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:discovery:2::el9"
}
}
}
],
"category": "product_family",
"name": "Red Hat Discovery 2"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Satellite 6",
"product": {
"name": "Red Hat Satellite 6",
"product_id": "red_hat_satellite_6",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:satellite:6"
}
}
}
],
"category": "product_family",
"name": "Red Hat Satellite 6"
},
{
"branches": [
{
"category": "product_name",
"name": "Self-service automation portal 2",
"product": {
"name": "Self-service automation portal 2",
"product_id": "self-service_automation_portal_2",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:ansible_portal:2"
}
}
}
],
"category": "product_family",
"name": "Self-service automation portal 2"
},
{
"category": "product_version",
"name": "ansible-automation-platform-24/lightspeed-rhel8",
"product": {
"name": "ansible-automation-platform-24/lightspeed-rhel8",
"product_id": "ansible-automation-platform-24/lightspeed-rhel8",
"product_identification_helper": {
"purl": "pkg:oci/lightspeed-rhel8?repository_url=registry.redhat.io/ansible-automation-platform-24/lightspeed-rhel8"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-25/lightspeed-rhel8",
"product": {
"name": "ansible-automation-platform-25/lightspeed-rhel8",
"product_id": "ansible-automation-platform-25/lightspeed-rhel8",
"product_identification_helper": {
"purl": "pkg:oci/lightspeed-rhel8?repository_url=registry.redhat.io/ansible-automation-platform-25/lightspeed-rhel8"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-26/controller-rhel9",
"product": {
"name": "ansible-automation-platform-26/controller-rhel9",
"product_id": "ansible-automation-platform-26/controller-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/controller-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-26/controller-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-26/eda-controller-rhel9",
"product": {
"name": "ansible-automation-platform-26/eda-controller-rhel9",
"product_id": "ansible-automation-platform-26/eda-controller-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/eda-controller-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-26/eda-controller-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-26/gateway-rhel9",
"product": {
"name": "ansible-automation-platform-26/gateway-rhel9",
"product_id": "ansible-automation-platform-26/gateway-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/gateway-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-26/gateway-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-26/hub-rhel9",
"product": {
"name": "ansible-automation-platform-26/hub-rhel9",
"product_id": "ansible-automation-platform-26/hub-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/hub-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-26/hub-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-26/lightspeed-rhel9",
"product": {
"name": "ansible-automation-platform-26/lightspeed-rhel9",
"product_id": "ansible-automation-platform-26/lightspeed-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/lightspeed-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-26/lightspeed-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
"product": {
"name": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
"product_id": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/aap-cloud-billing-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-27/aap-cloud-billing-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-27/controller-rhel9",
"product": {
"name": "ansible-automation-platform-27/controller-rhel9",
"product_id": "ansible-automation-platform-27/controller-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/controller-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-27/controller-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-27/eda-controller-rhel9",
"product": {
"name": "ansible-automation-platform-27/eda-controller-rhel9",
"product_id": "ansible-automation-platform-27/eda-controller-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/eda-controller-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-27/gateway-rhel9",
"product": {
"name": "ansible-automation-platform-27/gateway-rhel9",
"product_id": "ansible-automation-platform-27/gateway-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/gateway-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-27/gateway-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-27/hub-rhel9",
"product": {
"name": "ansible-automation-platform-27/hub-rhel9",
"product_id": "ansible-automation-platform-27/hub-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/hub-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-27/hub-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-27/lightspeed-rhel9",
"product": {
"name": "ansible-automation-platform-27/lightspeed-rhel9",
"product_id": "ansible-automation-platform-27/lightspeed-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/lightspeed-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-27/lightspeed-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-27/metrics-service-rhel9",
"product": {
"name": "ansible-automation-platform-27/metrics-service-rhel9",
"product_id": "ansible-automation-platform-27/metrics-service-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/metrics-service-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-27/metrics-service-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform/automation-dashboard-rhel9",
"product": {
"name": "ansible-automation-platform/automation-dashboard-rhel9",
"product_id": "ansible-automation-platform/automation-dashboard-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/automation-dashboard-rhel9?repository_url=registry.redhat.io/ansible-automation-platform/automation-dashboard-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
"product": {
"name": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
"product_id": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/metrics-service-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-tech-preview/metrics-service-rhel9"
}
}
},
{
"category": "product_version",
"name": "automation-controller.src",
"product": {
"name": "automation-controller.src",
"product_id": "automation-controller.src",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/automation-controller@4.5.33-1.el9ap?arch=src"
}
}
},
{
"category": "product_version",
"name": "discovery/discovery-server-rhel9",
"product": {
"name": "discovery/discovery-server-rhel9",
"product_id": "discovery/discovery-server-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/discovery-server-rhel9?repository_url=registry.redhat.io/discovery/discovery-server-rhel9"
}
}
},
{
"category": "product_version",
"name": "satellite/iop-advisor-backend-rhel9",
"product": {
"name": "satellite/iop-advisor-backend-rhel9",
"product_id": "satellite/iop-advisor-backend-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/iop-advisor-backend-rhel9?repository_url=registry.redhat.io/satellite/iop-advisor-backend-rhel9"
}
}
},
{
"category": "product_version",
"name": "ansible-automation-platform/bootc-automation-portal-rhel9",
"product": {
"name": "ansible-automation-platform/bootc-automation-portal-rhel9",
"product_id": "ansible-automation-platform/bootc-automation-portal-rhel9",
"product_identification_helper": {
"purl": "pkg:oci/bootc-automation-portal-rhel9?repository_url=registry.redhat.io/ansible-automation-platform/bootc-automation-portal-rhel9"
}
}
}
],
"category": "vendor",
"name": "Red Hat"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-24/lightspeed-rhel8 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8"
},
"product_reference": "ansible-automation-platform-24/lightspeed-rhel8",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-25/lightspeed-rhel8 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8"
},
"product_reference": "ansible-automation-platform-25/lightspeed-rhel8",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-26/controller-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/controller-rhel9"
},
"product_reference": "ansible-automation-platform-26/controller-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-26/eda-controller-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/eda-controller-rhel9"
},
"product_reference": "ansible-automation-platform-26/eda-controller-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-26/gateway-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/gateway-rhel9"
},
"product_reference": "ansible-automation-platform-26/gateway-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-26/hub-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/hub-rhel9"
},
"product_reference": "ansible-automation-platform-26/hub-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-26/lightspeed-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-rhel9"
},
"product_reference": "ansible-automation-platform-26/lightspeed-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-27/aap-cloud-billing-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/aap-cloud-billing-rhel9"
},
"product_reference": "ansible-automation-platform-27/aap-cloud-billing-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-27/controller-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/controller-rhel9"
},
"product_reference": "ansible-automation-platform-27/controller-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-27/eda-controller-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/eda-controller-rhel9"
},
"product_reference": "ansible-automation-platform-27/eda-controller-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-27/gateway-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/gateway-rhel9"
},
"product_reference": "ansible-automation-platform-27/gateway-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-27/hub-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/hub-rhel9"
},
"product_reference": "ansible-automation-platform-27/hub-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-27/lightspeed-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-rhel9"
},
"product_reference": "ansible-automation-platform-27/lightspeed-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-27/metrics-service-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/metrics-service-rhel9"
},
"product_reference": "ansible-automation-platform-27/metrics-service-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform-tech-preview/metrics-service-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-tech-preview/metrics-service-rhel9"
},
"product_reference": "ansible-automation-platform-tech-preview/metrics-service-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform/automation-dashboard-rhel9 as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform/automation-dashboard-rhel9"
},
"product_reference": "ansible-automation-platform/automation-dashboard-rhel9",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "automation-controller.src as a component of Red Hat Ansible Automation Platform 2",
"product_id": "red_hat_ansible_automation_platform_2:automation-controller.src"
},
"product_reference": "automation-controller.src",
"relates_to_product_reference": "red_hat_ansible_automation_platform_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "discovery/discovery-server-rhel9 as a component of Red Hat Discovery 2",
"product_id": "red_hat_discovery_2:discovery/discovery-server-rhel9"
},
"product_reference": "discovery/discovery-server-rhel9",
"relates_to_product_reference": "red_hat_discovery_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "satellite/iop-advisor-backend-rhel9 as a component of Red Hat Satellite 6",
"product_id": "red_hat_satellite_6:satellite/iop-advisor-backend-rhel9"
},
"product_reference": "satellite/iop-advisor-backend-rhel9",
"relates_to_product_reference": "red_hat_satellite_6"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "ansible-automation-platform/bootc-automation-portal-rhel9 as a component of Self-service automation portal 2",
"product_id": "self-service_automation_portal_2:ansible-automation-platform/bootc-automation-portal-rhel9"
},
"product_reference": "ansible-automation-platform/bootc-automation-portal-rhel9",
"relates_to_product_reference": "self-service_automation_portal_2"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-53878",
"cwe": {
"id": "CWE-113",
"name": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')"
},
"discovery_date": "2026-07-06T11:43:18.943000+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2497329"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Django. django.core.validators.DomainNameValidator accepted newline characters in domain name input. When applications use this validator outside Django form fields and include the validated value in HTTP response headers, a remote attacker could perform HTTP header injection. Django core is not affected because HttpResponse rejects newlines in headers, and CharField strips newlines by default.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "django: Django: HTTP header injection via DomainNameValidator accepting newlines",
"title": "Vulnerability summary"
},
{
"category": "other",
"text": "This flaw has a Low impact on Red Hat products. A vulnerability in Django's `DomainNameValidator` allows newline characters, which could enable HTTP header injection if validated values are directly used in HTTP response headers outside of Django's standard form handling. However, Django's core HTTP response mechanisms and default form field behaviors prevent this issue in typical deployments by rejecting or stripping newline characters. Exploitation requires a specific, non-default application implementation.",
"title": "Statement"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"known_affected": [
"red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/aap-cloud-billing-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-tech-preview/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform/automation-dashboard-rhel9",
"red_hat_ansible_automation_platform_2:automation-controller.src",
"red_hat_discovery_2:discovery/discovery-server-rhel9",
"red_hat_satellite_6:satellite/iop-advisor-backend-rhel9",
"self-service_automation_portal_2:ansible-automation-platform/bootc-automation-portal-rhel9"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-53878"
},
{
"category": "external",
"summary": "RHBZ#2497329",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497329"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-53878",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-53878"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-53878",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53878"
}
],
"release_date": "2026-07-07T14:00:00+00:00",
"remediations": [
{
"category": "workaround",
"details": "To mitigate this issue, ensure that custom Django applications do not directly place values validated by `DomainNameValidator` into HTTP response headers without further sanitization. Applications should rely on Django's default form handling and `HttpResponse` functionality, which automatically prevent newline injection. If direct header manipulation is unavoidable, implement explicit input sanitization to remove newline characters before constructing HTTP response headers.",
"product_ids": [
"red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/aap-cloud-billing-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-tech-preview/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform/automation-dashboard-rhel9",
"red_hat_ansible_automation_platform_2:automation-controller.src",
"red_hat_discovery_2:discovery/discovery-server-rhel9",
"red_hat_satellite_6:satellite/iop-advisor-backend-rhel9",
"self-service_automation_portal_2:ansible-automation-platform/bootc-automation-portal-rhel9"
]
},
{
"category": "none_available",
"details": "Fix deferred",
"product_ids": [
"red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/aap-cloud-billing-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-tech-preview/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform/automation-dashboard-rhel9",
"red_hat_ansible_automation_platform_2:automation-controller.src",
"red_hat_discovery_2:discovery/discovery-server-rhel9",
"red_hat_satellite_6:satellite/iop-advisor-backend-rhel9",
"self-service_automation_portal_2:ansible-automation-platform/bootc-automation-portal-rhel9"
]
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/aap-cloud-billing-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-tech-preview/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform/automation-dashboard-rhel9",
"red_hat_ansible_automation_platform_2:automation-controller.src",
"red_hat_discovery_2:discovery/discovery-server-rhel9",
"red_hat_satellite_6:satellite/iop-advisor-backend-rhel9",
"self-service_automation_portal_2:ansible-automation-platform/bootc-automation-portal-rhel9"
]
}
],
"threats": [
{
"category": "impact",
"details": "Low",
"product_ids": [
"red_hat_ansible_automation_platform_2:ansible-automation-platform-24/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-25/lightspeed-rhel8",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/aap-cloud-billing-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/eda-controller-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/gateway-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/hub-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-27/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform-tech-preview/metrics-service-rhel9",
"red_hat_ansible_automation_platform_2:ansible-automation-platform/automation-dashboard-rhel9",
"red_hat_ansible_automation_platform_2:automation-controller.src",
"red_hat_discovery_2:discovery/discovery-server-rhel9",
"red_hat_satellite_6:satellite/iop-advisor-backend-rhel9",
"self-service_automation_portal_2:ansible-automation-platform/bootc-automation-portal-rhel9"
]
}
],
"title": "django: Django: HTTP header injection via DomainNameValidator accepting newlines"
}
]
}