RHSA-2026:73377HighCVSS 8.6

Red Hat Security Advisory: OpenShift Virtualization v4.12 Images

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization

🎯 Affected products2

  • Red Hat Container Native Virtualization 4.12
  • registry.redhat.io/container-native-virtualization/kubevirt-console-plugin@sha256:9ea6a096a6832c2572879c698916962a99cf3fc678c3c75b76b54018807e969b_amd64 as a component of Red Hat Container Native Virtualization 4.12

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)