Red Hat Security Advisory: OpenShift Virtualization v4.13 Images
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products3
- Red Hat Container Native Virtualization 4.13
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:1151a81a6eb42e62756f6db8aa047e73761bd8cd6543cf01d75c1c55b406154a_arm64 as a component of Red Hat Container Native Virtualization 4.13
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:d2c9474723bd014ddd5a4d93f901feb369ca601cfbe749f132d729fd75ccb435_amd64 as a component of Red Hat Container Native Virtualization 4.13
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:53735
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/cve/CVE-2026-49978
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53735.json