Red Hat Security Advisory: OpenShift Virtualization v4.18 Images
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products4
- Red Hat Container Native Virtualization 4.18
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:33661b5b6b8055d7a58857f5824b8348011d18fdc1d66754d7b6c2069883e4fa_amd64 as a component of Red Hat Container Native Virtualization 4.18
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:af404cc981c8cc522f9702e2c225b83c050a12c4ef7162ce3a7591b0cd747929_s390x as a component of Red Hat Container Native Virtualization 4.18
- registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:c4b06d184d2c58d282bd419796f0312e9d4d94cf92d1affe58ad09c275de0a60_arm64 as a component of Red Hat Container Native Virtualization 4.18
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:53835
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53835.json