RHSA-2026:53736HighCVSS 8.1

Red Hat Security Advisory: OpenShift Virtualization v4.19 Images

Published
August 11, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products4

  • Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:320e96f868c3ce70956edf410f6c9f6422a47e80a876be7f31a2f4e066be8d7e_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:d7dc71440fbb6cf21967c1d80b1d351aea4e41fee2e4fc4560fc116619b3668e_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:e8eaac9da2099b14f2a5f0aa2aa7a75b6758eaf650afb2dca86acd135236bc0c_amd64 as a component of Red Hat Container Native Virtualization 4.19

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (5)