CVE-2026-74247
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.2
Source: NVD
Description
A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.
Affected (2)
Products: Redhat: Openshift Update Service, Quay
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 3.0.0 |
References (2)
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Timeline
No history available yet.