CVE-2026-32589

high
Published 2026-04-08 · Modified 2026-06-03
CVSS v3
7.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CVSS v4 NEW
—
not yet in upstream
VIR risk
7.4

Description

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.

Predictions

Exploit likelihood
82%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description mirror-registry: quay: insecure direct object reference in BlobUpload Red Hat statement Exploitation requires valid login credentials to the Quay registry. Unauthenticated users cannot exploit this flaw. CVSS v3: 7.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Quay…

Description

mirror-registry: quay: insecure direct object reference in BlobUpload

Red Hat statement

Exploitation requires valid login credentials to the Quay registry. Unauthenticated users cannot exploit this flaw.

CVSS v3: 7.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Quay 3.14quay/quay-rhel8:1779689392RHSA-2026:210172026-05-26T00:00:00Z
Red Hat Quay 3.16quay/quay-rhel9:1779204086RHSA-2026:193752026-05-19T00:00:00Z

Package state

ProductPackageState
mirror registry for Red Hat OpenShiftopenshift/mirror-registry-rhel8Affected
mirror registry for Red Hat OpenShift 2openshift/mirror-registry-rhel8Not affected

Apply commands

bash fix
Apply RHSA-2026:21017 for Red Hat Quay 3.14
yum update -y quay/quay-rhel8:1779689392
# or:
dnf upgrade -y quay/quay-rhel8:1779689392

Affected

VendorProductVersion
redhatmirror registry for Red Hat OpenShiftAffected
redhatmirror registry for Red Hat OpenShift 2Not affected

Application impact

VendorProductVersionsFixed
redhat redhatmirror_registry_for_red_hat_openshift-
redhat redhatmirror_registry_for_red_hat_openshift2.0
redhat redhatquay3.0.0

References

CWEs

CWE-639

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.