Migration Toolkit for Virtualization
Migrates virtual machines at scale to Red Hat OpenShift Virtualization. This gives organizations the ability to more easily access workloads running on virtual machines, while developing new cloud-native applications. Migrations are performed in a few simple steps, first by providing source and destination credentials, then mapping the source and destination infrastructure and creating a choreographed plan, and finally, executing the migration effort.
Browse the latest documentation
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Moderate | Advisory/CVECVE-2026-65902 | Synopsis A flaw was found in DOMPurify. An attacker can exploit a vulnerability in how DOMPurify handles its sanitization hooks when default configurations are used. By manipulating the uponSanitizeElement or uponSanitizeAttribute hooks, an attacker can permanently alter the allowed HTML tags and attributes. This allows malicious content to bypass sanitization, potentially leading to cross-site scripting (XSS) attacks and compromising the integrity of web applications. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65901 | Synopsis A flaw was found in DOMPurify. This cross-site scripting (XSS) vulnerability exists in IN_PLACE mode, where the software trusts attacker-controlled nodeName on live non-form nodes. A remote attacker can supply hostile live Document Object Model (DOM) objects with script children. These scripts can execute when the sanitized tree is inserted into a live document, potentially leading to information disclosure or arbitrary code execution. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65899 | Synopsis A flaw was found in DOMPurify where the clearConfig() function does not properly reset the retained Trusted Types policy. This can lead to a DOMPurify instance, when reused across different security contexts, remaining bound to a previously supplied and potentially unsafe policy. An attacker could leverage this to execute malicious scripts, resulting in client-side arbitrary code execution. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65898 | Synopsis A flaw was found in DOMPurify. When the `setConfig()` function is used with an `uponSanitizeAttribute` hook, the `ALLOWED_ATTR` allowlist is not properly cloned. This allows an attacker to register a hook that can permanently modify the shared allowlist, enabling the conditional allowance of dangerous attributes. Consequently, an attacker can submit untrusted content that inherits the polluted allowlist, leading to stored Cross-site Scripting (XSS) and the execution of event handlers. | Date |
| Severity Moderate | Advisory/CVECVE-2026-15792 | Synopsis A flaw was found in BuildKit. A malicious BuildKit client or frontend can craft a specially designed request, leading to the BuildKit daemon crashing. This vulnerability results in a denial of service (DoS), making the BuildKit service unavailable. | Date |
Top resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Go to toolkit
Migrate virtual machines to Red Hat OpenShift Virtualization.
Migrate virtual machines with Red Hat
Click through for a high-level overview of Red Hat's virtualization migration solution.
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.