Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-47428 — vitest: Vitest: Arbitrary code execution via crafted browser-runner URL CVE-2026-47429 — vitest: Vitest: Arbitrary code execution and information disclosure via path traversal
🎯 Affected products4
- Red Hat Hardened Images
- prometheus3-13-main@aarch64 as a component of Red Hat Hardened Images
- prometheus3-13-main@src as a component of Red Hat Hardened Images
- prometheus3-13-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: No mitigation is required for Red Hat shipping products, as the vulnerable @vitest/browser package and Browser Mode feature are not present or enabled in any Red Hat product. Development teams using Vitest as a build/test-time dependency should avoid introducing @vitest/browser or enabling Browser Mode in CI/local environments, and should upgrade to Vitest >=4.1.6 (or >=5.0.0-beta.3 on the 5.x beta line) where Vitest is used, as a matter of general hygiene. Workaround: No mitigation is required for Red Hat products, as none run Vitest's UI/API server or Browser Mode in their build or shipped runtime. Developers who run `vitest --ui`, `vitest --api`, or Browser Mode interactively should avoid binding the server to a non-localhost host, and should upgrade to vitest >= 4.1.0 (or >= 3.2.5 on the 3.x branch), where the allowWrite/allowExec flags default to disabled whenever the server is bound to a non-localhost host.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:39058
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-47428
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-47429
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_39058.json