Red Hat OpenShift Virtualization
OpenShift Virtualization is an add-on to OpenShift Container Platform that allows you to run and manage virtual machine workloads alongside container workloads.
Browse the latest documentation
DocumentationVirtualization
Release NotesVirtualization
Migration documentationMigrate
Training coursesLearn
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Important | Advisory/CVECVE-2026-71235 | Synopsis A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this vulnerability by creating rules with embedded Go or Lua scripts. These scripts are executed server-side without sufficient validation, allowing for arbitrary file read and write operations, access to internal databases, and Server-Side Request Forgery (SSRF) against internal microservices. This could lead to significant data compromise and unauthorized system access. | Date |
| Severity Moderate | Advisory/CVECVE-2026-15792 | Synopsis A flaw was found in BuildKit. A malicious BuildKit client or frontend can craft a specially designed request, leading to the BuildKit daemon crashing. This vulnerability results in a denial of service (DoS), making the BuildKit service unavailable. | Date |
| Severity Important | Advisory/CVECVE-2026-49852 | Synopsis A flaw was found in the joserfc Python library. A remote attacker can exploit a vulnerability in the `joserfc.jwt.decode` function to forge HMAC-signed tokens. This occurs because the library accepts tokens signed with an empty or null verification key, allowing an attacker to bypass integrity checks. Successful exploitation could lead to an integrity compromise of data processed by the library. | Date |
| Severity Moderate | Advisory/CVECVE-2026-42501 | Synopsis A flaw was found in the Go command (`cmd/go`). A malicious module proxy can exploit this vulnerability by bypassing the validation of module checksums. This allows the proxy to serve altered versions of the Go toolchain, which the `go` command may then download and execute without proper verification. This can lead to the execution of untrusted code, compromising the integrity of the Go development environment. | Date |
| Severity Important | Advisory/CVECVE-2025-47913 | Synopsis A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an unexpected message type, which the client code does not handle, leading to panic("unreachable") or a nil-pointer dereference. A malicious agent or forwarded connection can exploit this to terminate the client process. | Date |
Top resources
Lifecycle
Product life cycle
Documentation
Documentation
Product info
Access resources you need to be successful.
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.