Skip to main content
EPSS 0.4%top 70%

Red Hat Security Advisory: OpenShift Virtualization v4.12 Images

0
High
Published: 08/31/2026 (08/31/2026, 14:35:43 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

CVE-2026-67320 is a high severity vulnerability affecting Red Hat OpenShift Virtualization v4.12 images. It involves a Prototype Pollution flaw in the axios library when used in Node.js with the HTTP adapter. This flaw allows attackers to manipulate request interceptors to revert hardened request configurations, enabling them to route plaintext HTTP requests through a malicious proxy. This can lead to exposure of sensitive data such as authentication headers and request bodies, and potentially allow attackers to return malicious responses. Red Hat has acknowledged the issue but has not yet released a patch for affected versions.

Affected software

axios
pkg:npm/axios
Affected versions
>=0.31.1 <0.33.0>=1.15.2 <1.18.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 15:22:03 UTC

Technical Analysis

The vulnerability CVE-2026-67320 affects the axios HTTP client library used in Node.js deployments, specifically when using the HTTP adapter. Due to Prototype Pollution, request interceptors can revert hardened request configurations, allowing an attacker to manipulate the Object.prototype.proxy property. This manipulation enables attackers to route affected plaintext HTTP requests through a malicious proxy, potentially exposing sensitive information like authentication headers and request bodies, and allowing attackers to return their own responses. This vulnerability is present in Red Hat OpenShift Virtualization v4.12 images, specifically in versions >=0.31.1 <0.33.0 and >=1.15.2 <1.18.0 of the affected components. Red Hat has not provided a patch yet but has issued advisories describing the issue and its impact.

Potential Impact

If exploited, this vulnerability allows an attacker to intercept and manipulate HTTP requests by routing them through a malicious proxy. This can lead to disclosure of sensitive information such as authentication headers and request bodies, and potentially allow the attacker to inject malicious responses. The integrity of application data can be compromised, and unauthorized code execution or command injection could occur depending on context. The vulnerability is rated as high severity by Red Hat.

Mitigation Recommendations

Red Hat has not yet released a patch or fix for this vulnerability. Users are advised to ensure all previously released errata relevant to their system have been applied. Monitor Red Hat advisories for updates and apply fixes once available. No vendor-provided mitigations or workarounds are currently documented. Customers with a Red Hat Technical Account Manager (TAM) can consult directly for guidance. Patch status is not yet confirmed — check the Red Hat advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-68jp-44vc-2x5h
Osv Schema Version
1.4.0
Aliases
["CVE-2026-67320"]
Database Specific Severity
HIGH
Cvss Version
4.0

Threat ID: 6a6e6293bf32cb7a344f68c6

Added to database: 08/01/2026, 21:18:11 UTC

Last enriched: 09/09/2026, 15:22:03 UTC

Last updated: 09/15/2026, 22:01:36 UTC

Views: 79

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses