RHSA-2025:23176HighCVSS 7.5

Red Hat Security Advisory: Red Hat Quay 3.13.10

Published
December 15, 2025
Last Modified
August 19, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2024-34156 — encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion CVE-2025-47913 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS CVE-2025-59420 — authlib: Authlib RFC violation CVE-2025-61920 — authlib: Authlib Denial of Service

🎯 Affected products32

  • Red Hat Quay 3.13
  • registry.redhat.io/quay/clair-rhel8@sha256:1342015f8900bc707d1f83ec9cce6d73a63be03ca39f15952d7c30188a5358df_arm64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/clair-rhel8@sha256:1badbeb73cfe6c33bbff6922f778fe967bccbaaff72898a391d02880e765aad7_ppc64le as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/clair-rhel8@sha256:3824fc5efcc434b7af55f83541186eebe666e106f22856daec3844c32a80ac41_amd64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/clair-rhel8@sha256:625daa899431d9a6526e65c8834435cd4b065cc9ad36406023f1ba3820032e9a_s390x as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:bd1a02c47b6c32010fe19de6a994577b2c49ed692606d185d4252bb5ba347ecb_amd64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:32d1326be0b497a153790a58572bb83555d7fe756e782d719d31fd0912769bf4_amd64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:45b58ff658a6736e113db8b69f1e762bf8ead59110903f5a2adc16ebf6cb532e_s390x as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:8f2d0fc57d36feafb662d28136ebec46bad9047640cf126f2f4f49777ef5b357_ppc64le as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:b416224b4baa5a3c8663454f355aee800e327b28c6f19e0618b64b55f8daaf37_arm64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:042fad54f97a923749bb9e28357f44c9ad55cc3e02ebd93386170d90aba8aed0_arm64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:83ed8f834f7f93e91ef92c4e62dd37ad41149a52a8feecc5221daff3eb24ec27_ppc64le as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:92f9ae720c5c444a3e81ca42987152a689d2eaaa661e28b4cbc0363f1eaf56ce_s390x as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:f635f510c78e52dedc4cbd4b721cc98446a58a03d6f245713e3aaf6ba6f6dd57_amd64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:0bb986d4f52cef09dd9a104660426a69d1f2c252b2f604758ae39a7cbaf7ee9b_amd64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:5e4bfa8a9a4aa227922af4e35dcb3f659d1672d53c4c79bc35d0594b7cabbae7_s390x as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:6b8ae3a48b6237c6c689f1e62b3bb4eea645b5a3797a4e09e4a308f84f0c9ee7_arm64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:8e4a2e7576bdf731816856a1c24c8d18292fe01df37393f845111a6df18b61a8_ppc64le as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:c0a8c5f5454426844c43f8732ed512ab30b5d4bd3e799fa3f133670d0ea431d5_amd64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:38bcfcb8b18b9d0a84b108c9fde55fcda053c7cdbfc6f99639dd32d05f964756_s390x as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:9dd0249bc2ed6b1c2b26de52217d491204c925df3012df3ee3aeaaaa52b831b0_amd64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:faba929adc7958495dae063add6f0e67b5c2a92cd5848b16e88654aec51cb5a9_arm64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:fdee61c8dad676392456956ee47d5404f4b7bbf341453322d14feb71eb7660ab_ppc64le as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-operator-bundle@sha256:e3bda08789b2ba41154d080a5f013ee0e2406d60f8414e63be451a6439555cc1_amd64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:711b4047d6732b195af78cda60bdc7baba8fc64ec3bc67e566aab05f14ef54f6_s390x as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:71895379c0dca4fca449a1aee75d8aad06e1e72be3dee726cbe4c4f8fbe84fe2_arm64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:9598f801ee479cb633d512b63a95659e05dbbd8d867e383dca5867f09e97e145_amd64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:a152946ac895db8778f8db536f644a8a8b54f5db329918a8a9442e7aa729dc8c_ppc64le as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-rhel8@sha256:0b00334468578780a4e4b34c03260e57aa07ec47b0d4860b17c8ec964eb7634d_arm64 as a component of Red Hat Quay 3.13
  • registry.redhat.io/quay/quay-rhel8@sha256:1d15d8b7f90327a4216efba353d61c94a9438e5a8df3e68da44907816943d0d3_ppc64le as a component of Red Hat Quay 3.13
  • +2 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11358 Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Users unable to upgrade may manually enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

🔗 References (7)