container-native-virtualization/virt-handler vulnerabilities
CVEs whose affected-version data names the container-native-virtualization/virt-handler package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-13622High· 8.8A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symli…
▾ TwilightRed Hat · container-native-virtualization/virt-handlerEPSS 0.16%via NVD
CVE-2026-7374Critical· 9.9A flaw was found in KubeVirt's virt-handler component
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine consol…
▾ MidnightRed Hat · kubevirtEPSS 0.74%via NVD