The openshift-metal3/fakefish project is affected by a vulnerability where scripts inject shell variables without proper quoting, potentially allowing command injection attacks. This vulnerability, tracked as CVE-2026-71567, has a CVSS score of 7.7 and is classified as HIGH severity. The vulnerability primarily affects Image URL and BMC credentials configurations. Organizations should review their configu [truncated]
CVE-2026-71566 is a critical vulnerability in FakeFish, allowing unauthorized control of VMs by passing incoming credentials to scripts. This works because, ultimately, it's up to the BMC to validate them for real hardware. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. The vulnerability has a CVSS score of 9.3 and is considered critical. Use [truncated]