← Back

CVE-2026-2376

nvd nist
Published: Mar 12, 2026Modified: Jun 2, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.

Affected (2)

2 products
Quay
Mirror Registry
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.0.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 9.0
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 8.0

References (3)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingPatch

Timeline

No history available yet.