Red Hat Security Advisory: OpenShift Virtualization v4.20 Images
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products4
- Red Hat Container Native Virtualization 4.20
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:5682297da4876af1559f73a4633847bc9b334e40cac2fb3c1d659e8654177c76_s390x as a component of Red Hat Container Native Virtualization 4.20
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:b8e5cfe2d556df9297bf19963022128d5082bd06c25f517ecaf5938000c76fb3_amd64 as a component of Red Hat Container Native Virtualization 4.20
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:e583c4702a3cb9acaafc33e201fb7b258ca26c6ac8d4a9af84cdf15895ba1873_arm64 as a component of Red Hat Container Native Virtualization 4.20
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:53778
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53778.json