GHSA-h9q8-x6vm-q57fMediumCVSS 4.1

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with...

Published
May 29, 2026
Last Modified
May 29, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.

🔗 References (4)