RHSA-2026:36107HighCVSS 8.1
Red Hat Security Advisory: OpenShift Virtualization v4.15 Images
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-41240 — DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget
🎯 Affected products3
- Red Hat Container Native Virtualization 4.15
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:07290d11d241b0411d1a8b8c74082a16fa36b8422b302d0b98c45999e2d7ac0c_amd64 as a component of Red Hat Container Native Virtualization 4.15
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:462377766409e64c735558d1cc1b8379864e039612767cf31e6a906e3f0e7c30_arm64 as a component of Red Hat Container Native Virtualization 4.15
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:36107
- externalhttps://access.redhat.com/security/cve/CVE-2026-41240
- externalhttps://access.redhat.com/security/cve/CVE-2026-42044
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36107.json