RHBA-2025:3651HighCVSS 7.5

Red Hat Bug Fix Advisory: Red Hat Quay v3.13.5 bug fix release

Published
May 9, 2025
Last Modified
August 26, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2024-6827 — gunicorn: HTTP Request Smuggling in benoitc/gunicorn CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-22869 — golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh CVE-2025-27516 — jinja2: Jinja sandbox breakout through attr filter selecting format method

🎯 Affected products31

  • Quay v3
  • quay/clair-rhel8@sha256:7298f17b3894c919dc271dc60907ce22d53abf9727554ea50e52ee9f8bce73dc_s390x as a component of Quay v3
  • quay/clair-rhel8@sha256:92715751aef8fce39ba0e97d1a75a65b8d1ae7106d62486a1794b4d9bddbd687_ppc64le as a component of Quay v3
  • quay/clair-rhel8@sha256:a4b5b1c45db5708481908e024f7160cbe27e66d975e12f275cb02fbfeb08207b_amd64 as a component of Quay v3
  • quay/quay-bridge-operator-bundle@sha256:12242be8a33acdc8683b39fdf8e007baf7a35302527807eb0037d0ccef1cfe27_s390x as a component of Quay v3
  • quay/quay-bridge-operator-bundle@sha256:841fd2c720b174e3a6df84cb77350c8dbe1d6057198fbe372455fd9a776ae4ea_amd64 as a component of Quay v3
  • quay/quay-bridge-operator-bundle@sha256:8a4f63f5d129f75c3f53cea7bfd460df44f0f040e92663207c34bdb77255eebe_ppc64le as a component of Quay v3
  • quay/quay-bridge-operator-rhel8@sha256:1f494815365be08391ec325271c44100fb6167fb15ccf1c4155c7a0a6197b89b_amd64 as a component of Quay v3
  • quay/quay-bridge-operator-rhel8@sha256:d883983710064b866467b4db5766bcfefea8009895eae797e11f2663d0929544_ppc64le as a component of Quay v3
  • quay/quay-bridge-operator-rhel8@sha256:f871b4ba1aae82f6a635bc850219313b2118f75d8609c513f2d3846be208a561_s390x as a component of Quay v3
  • quay/quay-builder-qemu-rhcos-rhel8@sha256:0675d303e2a70ae0ae3133095e13c7ed630d02ce77ac83cee016e1b16a951971_s390x as a component of Quay v3
  • quay/quay-builder-qemu-rhcos-rhel8@sha256:ae4bef78094c03b766f1a47d4ff0f02302797455a28f7a15fa21ef50d31e026d_ppc64le as a component of Quay v3
  • quay/quay-builder-qemu-rhcos-rhel8@sha256:cc7ee29566143a2a0f61b1deb93687d28d3e13148afb833e93a37798d0f4dc32_amd64 as a component of Quay v3
  • quay/quay-builder-rhel8@sha256:254c389896555730eeeae17cb03ec6afc3230883bb2ac9c5722388a4d2de6ab3_amd64 as a component of Quay v3
  • quay/quay-builder-rhel8@sha256:4b730e73b8762a4e994d4d428c7ca96ec18c5480bbd7d5fdbfbeef0419c1b8ce_ppc64le as a component of Quay v3
  • quay/quay-builder-rhel8@sha256:b4f9dba37bf482ef415d5fbc233329ea13c9087dfd5a97cd6dbe0e85d0d1aa40_s390x as a component of Quay v3
  • quay/quay-container-security-operator-bundle@sha256:30f8e7bc7a7a72882720cd329dd8d9cebcb0dac3da04e211281129a88992f544_amd64 as a component of Quay v3
  • quay/quay-container-security-operator-bundle@sha256:9c0f9fd196b3b90c04ce314caa3730736b99edc2762d48cc2f998197ecfbd4d1_ppc64le as a component of Quay v3
  • quay/quay-container-security-operator-bundle@sha256:9ea22d519c7b086e27077f935590abc1d9ea2ea1a8db0ebf33ce2383d4b5775b_s390x as a component of Quay v3
  • quay/quay-container-security-operator-rhel8@sha256:34d3081bb600b37cc70827b341d2c54ffe5c6a973f19744ed3b5792e2ffb80b8_ppc64le as a component of Quay v3
  • quay/quay-container-security-operator-rhel8@sha256:b4e155c030b5f4dd8d84888262f6957ff261ec3ab6f484f04445c248bbd16594_s390x as a component of Quay v3
  • quay/quay-container-security-operator-rhel8@sha256:ca7062b086a57567b9a00b337c1b0d541c9886873f5de59a6408280e5b6e706c_amd64 as a component of Quay v3
  • quay/quay-operator-bundle@sha256:324e423b8bccb370ef85f9886515caac1c87fd36a8989dcfdaebda3e8f1062b1_ppc64le as a component of Quay v3
  • quay/quay-operator-bundle@sha256:3a6a4e98b434edc29e8ffa69d500e174e9003fec10559650b295bef3c8b0aa4a_s390x as a component of Quay v3
  • quay/quay-operator-bundle@sha256:635ec8aa2cbd5a2387656f615f1ffed7b54845df47780363c42383cdefc20196_amd64 as a component of Quay v3
  • quay/quay-operator-rhel8@sha256:4b8672d738c80f4aac2f66d740678938acea9b7509cb1746b81cdb9e728608f0_ppc64le as a component of Quay v3
  • quay/quay-operator-rhel8@sha256:c6b4d012500b017e0b3265eb9d1c1fb771d30e9a354f572362f69a6bf8f88a00_s390x as a component of Quay v3
  • quay/quay-operator-rhel8@sha256:e4ded1509a87c90f95f3fcddf4083b79929f5ec34ba7bb90741e8654691cdf2e_amd64 as a component of Quay v3
  • quay/quay-rhel8@sha256:11b133caf63b6543ecfe545c593941313ad5c62dd9ae1b3d6411e4a281321835_amd64 as a component of Quay v3
  • quay/quay-rhel8@sha256:35fa842fb2449cec085c3481f640d799a6883ed330f30cf352458fdcf8fe5eae_ppc64le as a component of Quay v3
  • +1 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat Product Security currently does not have a recommended mitigation at this time. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters. Workaround: This flaw can be mitigated when using the client only connecting to trusted servers.

🔗 References (4)