GHSA-rg7f-fcx2-cjw3MediumCVSS 4.2

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write...

Published
August 15, 2026
Last Modified
August 15, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.

🔗 References (4)