RHSA-2026:24833HighCVSS 7.1

Red Hat Security Advisory: Red Hat Quay 3.17.3

Published
June 9, 2026
Last Modified
August 8, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-32590 — mirror-registry: remote code execution using pickle deserialization CVE-2026-32591 — mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration

🎯 Affected products32

  • Red Hat Quay 3.17
  • registry.redhat.io/quay/clair-rhel9@sha256:679ca71c057aa259037602d5048e980cf2ce2d4baf3705be67b1d5f77611a446_s390x as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/clair-rhel9@sha256:9140673ad26107c3b712ebc5cdcc13a2a5b3e7ea9436236c48b7d84a4bada6e5_ppc64le as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/clair-rhel9@sha256:c04663199f7acd4121f9adfb576555c31fbe8efd0f70c2b487255bababdc2b8d_arm64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/clair-rhel9@sha256:e45aa07ebc859af01c63f56b49af0ad5ec077d2e43133fa8084962027be61cc2_amd64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:cb1de43146fd653a585d34989bd09d6911a8d1ee1710bbb5a43243c46ad16b55_amd64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:38e0f7faa1670ba3e735b4b471e5219d1e1d26491e0db773b0131273bd8a8986_ppc64le as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:76f859d0e15744c482e4477e2f5449041bdd2be92edde49534992f065750b40d_amd64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:ee83f98402a38e194c836dc065b5e1d421b4f66e113679c7d26d684343d9340a_arm64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:fe5a2456733463f133f7a437a68043b5d8f2cbe86a74733313e11dc5ded2fd33_s390x as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:00624a94a9c45d514eb09cdc85775ec2bfded9ddd0b64c5da61868f78977a16c_amd64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:05abf1c01f198c8df515fa7448bc352b37b161a7e6eab7101bce54f1895cf0ff_s390x as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:9bbc85c8e428c4837aeff0670e26ae576ebaf3d85428939c8d90afa8f5f86f13_ppc64le as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:e95a72e0e7f2b81fe7f0c762913492bcab9b3c87bdbcb25e7490d6f1b29ae241_arm64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:118054e2330adc3e62351954dd2c77032667d339c179e3f2d3239673aefdb69d_amd64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:2f602291300ce78e1cd48a8b8e329c113f3a9578599d7c1a84c40f873a6dbb68_ppc64le as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:6f6b1330a2dd5b6935654ab57c634c5a48bccd339c5a2eed4ef619fe3d9c2560_arm64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:86092ff3b8c8bcd3ca6ce548d7eaedc3773aeaa919dbec166a9926274c90cd15_s390x as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:c7827fe2034ee2d88d5cc9365f3f8ecc88431f2559742c48f7819ed08ba59763_amd64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:2b72f06f32f712b4d15e2afef2f5e6d524c7a5044439f3cc188185f1e2bd164f_s390x as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:2b94e6ae837e2ed18153451ac233ee947b932954dd826fcaed162123d0b6d6aa_ppc64le as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:65ccc872897544ca99937bf184d6ec74a963202fb8bcb258a700898e061b2a47_arm64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:e9ca0fbc73cb281418afa5fb4e42c011335f12f99a4b537fd06b02937a487c39_amd64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-operator-bundle@sha256:9e35a7389ecd676d5735a3a25117b61fc0e590acd4ec815a3b465934cd0578f9_amd64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:13fbc1d51bb3223c9a0925967344c906bbf7020d9330bbea4fe1655a541807a8_arm64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:235a82cfffe9d1a8d995770de6244b70a710c1abb5ef8a79a5f53aa7c45d4366_amd64 as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:393c1a9f8626926bc883468b65736e6ec42cc02d7a989fddf39bf38ebc58e57b_s390x as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:c87ce55416458d4d37e40aba0155447dd0be2210eaaf1a89d5056331c4bcb2ae_ppc64le as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-rhel9@sha256:17c8a5b1140935b38cea1dcb846049a3901f3f7932990a83f65e0fdce015cf78_ppc64le as a component of Red Hat Quay 3.17
  • registry.redhat.io/quay/quay-rhel9@sha256:5ffa091bf9859a0ad3902c92c71d6387ac68e358e9794c86709879e3fac1bb0f_amd64 as a component of Red Hat Quay 3.17
  • +2 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (5)