Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.6%top 53%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Critical
Published: 07/13/2026 (07/13/2026, 23:42:49 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A critical security flaw (CVE-2026-47428) was found in Vitest Browser Mode, allowing remote attackers to execute arbitrary JavaScript code via a crafted browser-runner URL. This could lead to unauthorized access to the VITEST_API_TOKEN and further system compromise. However, Red Hat products do not ship or enable the vulnerable @vitest/browser package or Browser Mode, and Vitest is only used as a build/test-time dependency without Browser Mode enabled. Therefore, Red Hat products are not affected by this vulnerability. No mitigation is required for Red Hat shipping products. Development teams using Vitest should avoid enabling Browser Mode and upgrade to Vitest versions 4.1.6 or later.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/24/2026, 16:07:56 UTC

Technical Analysis

CVE-2026-47428 is a vulnerability in Vitest's Browser Mode that permits remote code execution through a specially crafted browser-runner URL. This flaw can also expose the VITEST_API_TOKEN, enabling unauthorized authenticated API calls. Red Hat has confirmed that none of its shipping products install or enable the vulnerable @vitest/browser package or Browser Mode; Vitest is used only as a build/test-time devDependency without Browser Mode. Several affected Vitest streams have been patched in versions 4.1.6 and above. Consequently, Red Hat products are not reachable via this vulnerability. The advisory also references CVE-2026-47429 and includes fixes in Red Hat Hardened Images RPMs for prometheus3.13 packages, but no direct fixes for this CVE are needed in Red Hat products.

Potential Impact

If exploited in an environment where Vitest Browser Mode is enabled, this vulnerability allows remote attackers to execute arbitrary JavaScript code on the Vitest server and potentially access sensitive tokens, leading to unauthorized API calls and system compromise. However, Red Hat products do not include or enable the vulnerable component, so there is no impact on Red Hat shipping products. The vulnerability is critical in general but does not affect Red Hat's delivered software.

Mitigation Recommendations

No mitigation is required for Red Hat shipping products because the vulnerable @vitest/browser package and Browser Mode are not present or enabled. Development teams using Vitest as a build/test-time dependency should avoid introducing @vitest/browser or enabling Browser Mode in CI or local environments. They should upgrade to Vitest version 4.1.6 or later (or 5.0.0-beta.3 on the beta line) to ensure patched versions are used.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:39058
Cve Count
2
Additional Cves
["CVE-2026-47429"]
Cvss Version
null

Threat ID: 6a5d27b32a4a8d598913360f

Added to database: 07/19/2026, 19:38:27 UTC

Last enriched: 08/24/2026, 16:07:56 UTC

Last updated: 09/03/2026, 10:52:09 UTC

Views: 100

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses