RHSA-2026:39058CriticalCVSS 8.3

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
July 13, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-47428 — vitest: Vitest: Arbitrary code execution via crafted browser-runner URL CVE-2026-47429 — vitest: Vitest: Arbitrary code execution and information disclosure via path traversal

🎯 Affected products4

  • Red Hat Hardened Images
  • prometheus3-13-main@aarch64 as a component of Red Hat Hardened Images
  • prometheus3-13-main@src as a component of Red Hat Hardened Images
  • prometheus3-13-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: No mitigation is required for Red Hat shipping products, as the vulnerable @vitest/browser package and Browser Mode feature are not present or enabled in any Red Hat product. Development teams using Vitest as a build/test-time dependency should avoid introducing @vitest/browser or enabling Browser Mode in CI/local environments, and should upgrade to Vitest >=4.1.6 (or >=5.0.0-beta.3 on the 5.x beta line) where Vitest is used, as a matter of general hygiene. Workaround: No mitigation is required for Red Hat products, as none run Vitest's UI/API server or Browser Mode in their build or shipped runtime. Developers who run `vitest --ui`, `vitest --api`, or Browser Mode interactively should avoid binding the server to a non-localhost host, and should upgrade to vitest >= 4.1.0 (or >= 3.2.5 on the 3.x branch), where the allowWrite/allowExec flags default to disabled whenever the server is bound to a non-localhost host.

🔗 References (6)