RHSA-2026:25041HighCVSS 8.2

Red Hat Security Advisory: Red Hat Migration Toolkit for Containers

Published
June 10, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation CVE-2026-42033 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution CVE-2026-42035 — axios: Axios: Arbitrary HTTP header injection via prototype pollution CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data CVE-2026-42041 — axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling CVE-2026-42043 — axios: Axios: NO_PROXY bypass via crafted URL CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget

🎯 Affected products12

  • Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-controller-rhel8@sha256:0cba0be1e3a9b2372a3ac886ef4eab4df26477dfbc6c05cfb1a777cffc140cae_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-hook-runner-rhel8@sha256:3627ad1ad96e923f1df9351be45f577c3626337a7ddb655dfca7b37f072ce9cf_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-log-reader-rhel8@sha256:6ad18683cca4a6f3d79b01ef2cf77d14d5759513de664c885d0b0ecf806a127d_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-must-gather-rhel8@sha256:10353c1f0701f08fedb59a293cf9ac047142012f8970e45d43a235df086394d8_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-openvpn-rhel8@sha256:939aea38e821fdc02d57e36a6b29e8bee99cfce482cc4203a8f4c3b64229b123_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-operator-bundle@sha256:d464ca3699dbfe6a89d96bccc0816b531ec84d61bdf44ca99a29e562787f9889_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-registry-rhel8@sha256:937e190c974b9af97313524516e02f04adef637df5de3e3a2ff502e5e135c3e1_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-rhel8-operator@sha256:2c4a1b84c4a428102ed984cd565e3a2c3919cef093c7bab1f7ec0e2b4a3d8155_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:adabb068c94f2fcefe7d8924563a5a5d0fd32217bad330416d755de507c69334_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-ui-rhel8@sha256:dd0b544f95487c18174c922d7b0d979a457e84479bf93549bd152d2477f124bb_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8@sha256:d7da58f4a2ec52d420426957cdf640d589016db80ca8769fbfedadf17c735361_amd64 as a component of Red Hat Migration Toolkit 1.8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (12)