RHSA-2026:30076HighCVSS 8.1

Red Hat Security Advisory: Red Hat Quay 3.12.19

Published
June 25, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-10143 — kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens

🎯 Affected products29

  • Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:0285b52259e86295777d45ca169c63d5cc2ad320774fb36a83eb76b0ee906b62_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:6cbbd03b84fc2a72f0546b0f88564bdd30f694eef88699327afb94aadf6bded5_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:758da243753a713917e5d6ac61f7cb516be1f1f7714136ce1fa9c8c5383c6c91_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:92e7c9e7f90ac26681e680fd548e015a36e5760aa4ea8f8278e9ef052969dfcf_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:61cb89f4522d027dc7862cad2db1b0e6b8d0ee2c805e5bba5dfaa2f0a626b498_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:175cfaa83d23cb17e179d0f01a2b8c6b10a4ff0771616380421114fa46404c5e_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:2c13c569fcd307d333f26c098a2c0b2de9a7a0006974d98dae532e0189a7b384_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:73ba187acabd311914dd81494a5b32968fab6c8c0e943290569154e10dd2e6bb_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:8ef53d785bd058442d23ca8d7cfb5034830e75e963e764a3bb78b9c5bc782df7_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:4e18730e0d3a0297df2e97af0c5a16602fb3c45a1e6ef8f04339a1d6ef9f8ca7_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:31681014e706162350f17a91c3d2b348b6d930ade877839b8ddd35fadeaa4c7b_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:8326e2cf11416af5abcf9bf0c4a496dd6d42f90e03b9d83c10ab1b5c5537631d_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:8a0fd5087f811850d07a66718ba2f230ca1a3fa581bf88aa8be2c00fa907b88e_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:df86c2a14cd963c1efac3ef7375934ea4e432351bc45a441580d87e7da5db08f_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:876b89b047656b208af0f57881bb7ae351f53c2f875675686e5b334b74d2ac2b_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:804cfcb86df78455d539a984502f91e887b19caf8c633793a0173b481c0cd1e3_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:b00b2c5a96fe210d53ae11f4d21f507e0adf9c63257cdbc9ab199455771654d0_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:d7cc7f5b60db23e617782f514368fd3a20fc2e31051a7b0d13603d14c6386483_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:f43d26a782e2c0994598fa1bf4d57073e272717418ac62df6f1a394a9a4a9deb_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-bundle@sha256:3a939af325476612b7c753c10015c36a3ab43ae4a8751aee6877621d90ebfee9_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:168e8f94d1d818026c2c3f545f37aeeacfddc8181652f49408358a91010a771a_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:531d1c071f662ae600b6e0d6cb945bb13d9155330a2e5c01b19ba01920f46874_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:d977e222cce6e053bc206fa891215e2ece1bd0c6f87a916d0899c51dca3c4fcf_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:dd341c8af0f1c6aff634d99e0d145c0a2b10f2e8f0dd3b0929eb0f27888f772c_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:09cacc9bbd0ea8f666b392a278cda7d42bd36116ec696f722d294a4d2b8cc64b_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:b7002e08ebee80927d071a0c3348fb1e508e65cef47671f5554d740a74a8a6fc_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:b9e339cb611967965c68280227825dad1018524c5ff6bc0fcf5620b2581fce1c_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:db1bcca3650cdc99b46ab8c11b138220a0c90eb7475d7e36c026ebd7a57e02dd_s390x as a component of Red Hat Quay 3.12

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)