Red Hat Security Advisory: Red Hat Quay 3.9.23
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-10143 — kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
🎯 Affected products23
- Red Hat Quay 3.9
- registry.redhat.io/quay/clair-rhel8@sha256:0ed9d3a90f5b0f2adaba21b49ef3c629d69fd3554f38d2a26525b2fdad3d4fe8_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/clair-rhel8@sha256:36dc50c6b2b176b98b05f0dce802794190122bd18ec265c40d0f9f4245b57564_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/clair-rhel8@sha256:654ef27ab24735981a6f28b743b13868f55ca94fdbd289cbbf136d4629eba75d_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:312b8a6031010e33f8df1c6e90ff63ee6ba5ec109d5c23acdfb1bb413e119a7d_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:25826b91cdcae78706045327f672a0544f4b9658a9914771b0fdab6a981e8bf8_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:44f88dd294f886ab69112ba29be6c04231018ad0d0192356386c4aee16207a5c_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:ab8f84e82313f91c17dc0b23b81a7c2aa1fc15a17e50c97e24f98936e99e67b2_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:68d268d572984190bdecf678eaba8275593549bb92b7ca518e5e6b1c820bcd75_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-builder-rhel8@sha256:391a8858036bed2cb05cf0c37d905a2f6c367f4705795cd83e181274f5aed41a_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-builder-rhel8@sha256:a8af9488daf49202bdcb7f6ecd113d65a4c73148cad818ce870c5bc0b9250bba_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-builder-rhel8@sha256:dda77e696c2272f8e172e04241e8d2cb3d3004c17759d36f5b3c520b6cd8850b_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:97f36276e98ba3d93763bfe7c921bca2f41ee4f7fbdbe6052aea28122f38259b_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:3e637bf12fb1c68ffbe8d278b7e9377dddd91d9d597daa6451de20b9dafa9111_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:4581e59d102f9bce89bb976b21d82551c1728b893106c6daa6bcbca222718340_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:6fb549bf38e1972c8b7694bd38c132d4559309da05d46c9d3ca06dee08edb1bc_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-operator-bundle@sha256:4e6449a8207bc33afc86df358ce021253040d871610c1a8681f61991b74cf121_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-operator-rhel8@sha256:0e9272374dc0faf6b8e69561f06ab5fc455999f7716ca57e4e4c811f049cb2ca_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-operator-rhel8@sha256:4ba90ed26dc4d0cb7ec9dcf0ba6ed23e33c5e0ae239e8e0fc258099d251184e4_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-operator-rhel8@sha256:6272448836f183b0b2e01598a5dcccb0c74fc35c91936e9eb5f32017d2a66f2b_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-rhel8@sha256:5b565745268aa52a83c9b145ef4abf1a6bb1f1aff7b08c64e461a5d959721a14_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-rhel8@sha256:6f58133b6e8c814219f6ffbc25119adae1facf42108d62c8271055e507af5b00_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-rhel8@sha256:cf6779d291c210b654b14bf86b229d4743fd5c66e04081b8f9796e4b6e0ea040_ppc64le as a component of Red Hat Quay 3.9
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:28571
- externalhttps://access.redhat.com/security/cve/CVE-2026-10143
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_28571.json