Red Hat Security Advisory: OpenShift Virtualization v4.12 Images
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products2
- Red Hat Container Native Virtualization 4.12
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin@sha256:91f0b7aa48e6d376398742fd6517a23fa9b07c5947493457ec9dd49a9609ae50_amd64 as a component of Red Hat Container Native Virtualization 4.12
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:46623
- externalhttps://access.redhat.com/security/cve/CVE-2026-49978
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_46623.json