Red Hat Security Advisory: OpenShift Virtualization v4.21 Images
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products4
- Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:653af0fce4b25b67b2c00bf52c20c5da3f297fac52a03bebc8e7619ae71a942e_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:9320ccd7b35b3a90e7a255a82a13b511727c94c35b45b15b3b2d30bded71db87_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:fb34de7d5bdfb9efd16eeff39b4e8495f8a749bb34f278e0b57ce64f5aa58f4d_s390x as a component of Red Hat Container Native Virtualization 4.21
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:53752
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53752.json