RHSA-2026:53840HighCVSS 8.1

Red Hat Security Advisory: OpenShift Virtualization v4.15 Images

Published
August 11, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products3

  • Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:2995ef25b6e747fb77d6c83a1184b8e7b0d20d4c64a9bc230d94e98d03e8c355_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:80462440b0f4f22bec249b45eec5f5e0f8810c8b6b0aadad76c7fb4515c3edf1_arm64 as a component of Red Hat Container Native Virtualization 4.15

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (7)