Red Hat Security Advisory: OpenShift Virtualization v4.14 Images
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products3
- Red Hat Container Native Virtualization 4.14
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:7fd18f7ed8509b9e90750c38b7732e032b32f9663d1fdfda8664b7c466581e27_arm64 as a component of Red Hat Container Native Virtualization 4.14
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:a6fc9b2cf08a62a043d614fd2011936fa09fde517f8cd6e2cb62a5f746b8c896_amd64 as a component of Red Hat Container Native Virtualization 4.14
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:53789
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53789.json