CVE-2026-27135 vulnerability in libnghttp2 for Automation Engine 24
search cancel

CVE-2026-27135 vulnerability in libnghttp2 for Automation Engine 24

book

Article ID: 454348

calendar_today

Updated On:

Products

Automic Automation

Issue/Introduction

Vulnerability scans or security assessments may identify a high-severity vulnerability (CVE-2026-27135) related to the libnghttp2 package in Automation Engine version 24.4.4 or lower. This vulnerability stems from an outdated version of the library bundled within the install-operator image. This article provides the remediation steps required to address this security finding.

Environment

Product: CA Automic Workload Automation 24.4.4

Component: install-operator image

Cause

Automation Engine version 24.4.4.1 utilizes a version of the libnghttp2 library susceptible to CVE-2026-27135 (an HTTP/2 assertion failure that enables remote Denial of Service).

Resolution

This vulnerability is resolved in Automation Engine version 24.4.5 and higher. Version 24.4.5 includes the updated, non-vulnerable libnghttp2 package (version 1.68.0-3.el10_2.1.x86_64).