CVE-2026-32591
- EPSS 0.33%
- Veröffentlicht 08.04.2026 17:06:58
- Zuletzt bearbeitet 22.09.2026 18:17:13
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it p...
CVE-2026-32590
- EPSS 0.41%
- Veröffentlicht 08.04.2026 17:04:22
- Zuletzt bearbeitet 09.09.2026 23:16:55
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay s...
CVE-2026-32589
- EPSS 0.24%
- Veröffentlicht 08.04.2026 17:04:20
- Zuletzt bearbeitet 10.09.2026 13:18:10
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have ...
CVE-2026-2377
- EPSS 0.41%
- Veröffentlicht 08.04.2026 16:26:07
- Zuletzt bearbeitet 10.09.2026 13:18:04
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this pro...
CVE-2026-2376
- EPSS 0.16%
- Veröffentlicht 12.03.2026 19:16:16
- Zuletzt bearbeitet 02.06.2026 19:23:46
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically fol...
CVE-2025-4374
- EPSS 0.32%
- Veröffentlicht 06.05.2025 14:49:28
- Zuletzt bearbeitet 07.08.2026 14:16:53
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
CVE-2024-9683
- EPSS 0.3%
- Veröffentlicht 17.10.2024 15:15:13
- Zuletzt bearbeitet 03.12.2024 16:14:52
A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement. While the risk is re...
CVE-2024-5891
- EPSS 0.23%
- Veröffentlicht 12.06.2024 14:15:12
- Zuletzt bearbeitet 21.11.2024 09:48:31
A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was created. This issue is limited to ...
CVE-2024-3623
- EPSS 0.43%
- Veröffentlicht 25.04.2024 18:15:09
- Zuletzt bearbeitet 21.01.2026 14:16:05
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-re...
CVE-2024-3622
- EPSS 0.52%
- Veröffentlicht 25.04.2024 18:15:09
- Zuletzt bearbeitet 30.07.2025 14:41:38
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to hav...