RHSA-2026:51028HighCVSS 7.5

Red Hat Security Advisory: OpenShift Virtualization v4.22 Images

Published
August 6, 2026
Last Modified
August 6, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products4

  • Red Hat Container Native Virtualization 4.22
  • registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:037ae22a3274a0674ebc9d9ea29cc24403ea20c2e21e2cd4d43f7acf4e769cb0_arm64 as a component of Red Hat Container Native Virtualization 4.22
  • registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:5d71337ae41180ff3c836ea11db86203414c2220f1a55d5c1aec145d0c6d4310_amd64 as a component of Red Hat Container Native Virtualization 4.22
  • registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:708de6ec0f7a5deb428ccfcca46f01b25a6cf72fe5a4705034e68e6fdca66138_s390x as a component of Red Hat Container Native Virtualization 4.22

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (4)