—
GO-2026-5848
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt
Quick fix
GO-2026-5848 — kubevirt.io/kubevirt: upgrade to the fixed version with the command below.
go get kubevirt.io/kubevirt@v1.6.6Details
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/advisories/GHSA-7jcp-v9w4-wjmg[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-7374[ADVISORY]
- https://access.redhat.com/errata/RHSA-2026:20720[WEB]
- https://access.redhat.com/errata/RHSA-2026:20736[WEB]
- https://access.redhat.com/errata/RHSA-2026:20763[WEB]
- https://access.redhat.com/errata/RHSA-2026:20767[WEB]
- https://access.redhat.com/errata/RHSA-2026:20782[WEB]
- https://access.redhat.com/errata/RHSA-2026:20825[WEB]
- https://access.redhat.com/errata/RHSA-2026:20866[WEB]
- https://access.redhat.com/errata/RHSA-2026:20886[WEB]
- https://access.redhat.com/errata/RHSA-2026:20890[WEB]
- https://access.redhat.com/errata/RHSA-2026:20975[WEB]
- https://access.redhat.com/security/cve/CVE-2026-7374[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2463728[WEB]
- https://github.com/kubevirt/kubevirt/commit/011eef8129e2c21e0ea496f283ee1676009bc757[WEB]
- https://github.com/kubevirt/kubevirt/pull/17916[WEB]
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7374.json[WEB]