6.8

CVE-2026-15927

Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation

A flaw was found in Red Hat Quay's repository-level mirror configuration
feature. The POST and PUT handlers in endpoints/api/mirror.py accept an
external_reference parameter without SSRF validation, unlike the
organization-level mirror handlers which apply validate_external_registry_url().
A repository administrator can supply a crafted hostname that causes the Quay
mirror worker to make requests via Skopeo to internal network services, cloud
metadata endpoints, or other resources not intended to be reachable from the
Quay application.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
Produkt Red Hat Quay 3.1
Default Statusaffected
Version 1786395065
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Quay 3.12
Default Statusaffected
Version 1786170635
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Quay 3.17
Default Statusaffected
Version 1786181981
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Quay 3.9
Default Statusaffected
Version 1785950004
Version < *
Status unaffected
HerstellerRed Hat
Produkt mirror registry for Red Hat OpenShift 2
Default Statusaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.208
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 6.8 2.3 4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

https://access.redhat.com/security/cve/CVE-2026-15927
https://bugzilla.redhat.com/show_bug.cgi?id=2501256
https://access.redhat.com/errata/RHSA-2026:50931
https://access.redhat.com/errata/RHSA-2026:52968
https://access.redhat.com/errata/RHSA-2026:53520
https://access.redhat.com/errata/RHSA-2026:54395