Red Hat Security Advisory: Red Hat Quay 3.10.23
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-10143 — kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
🎯 Affected products23
- Red Hat Quay 3.1
- registry.redhat.io/quay/clair-rhel8@sha256:25c740738b3511ae6333ad8f32e6c2eac1d3d4fe2c9eeda241906f0a6a96f708_ppc64le as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/clair-rhel8@sha256:9313307979bccd1f9bc732df389f1d6c49159ceb74ef9befbb7ae269afe9f9c1_s390x as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/clair-rhel8@sha256:e51e41b330d3cf44ef7b5eb1a511096cef98f82495297cd4438693ef2f9a24ef_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:c8a83d3757c774e0958472661f268783e17d7d0c7a7e4e19e1d380201c43e0d0_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:09933cf1e12617711f28f19798f355b3c064ab1219179b0692f591f5d1f86b2c_ppc64le as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:1a36faf3a63c2f367a1524748d9c4a56fb3910c80af4ead41c6c8a73b5b8eab8_s390x as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:a040e83b9aa90c795751c3163533571c954639fbad350a25f258a3ef2d9669d4_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:da8f01cb4aafaed7f2313329ab905cfd274133fc0b850cda8955d15898245153_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-builder-rhel8@sha256:3bf79d70954794dc237f44bbbae4bcec5a5b16fedb3eda79f4f26d3be04c6775_ppc64le as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-builder-rhel8@sha256:65b406622bfd9fadf0d24431277957bafc553d9e7b331f8357c1c7ef8535f0c9_s390x as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-builder-rhel8@sha256:d353d7214e8bef5f0ee1632da4e6f74bc89495115ab8ce245af5665fefbdb2ea_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:5040540e6ed9126958497b0b12d1d119eb06f445ca0edeb0f823880d5c936567_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:37510942aee22b6321acb0ef35464da20116b44809efd92a4666435d1a2bd732_s390x as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:89403ee27003086a0da369f2087718644bce09eb1571919ce809ea7d6b4e7eeb_ppc64le as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:b3d595075321c1cebed49970a2b3746d59415ef08fa4d800a8db58ad716638d0_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-operator-bundle@sha256:009f4d31d16d3f0a6f942efa8fa1aec77edc9b6f0aae38503b472c0e6bf6b615_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-operator-rhel8@sha256:1eb7d2e819dd5ca1c2062ce1812361d0fe8390cfeed9cc01a1500b8632bfd8c3_ppc64le as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-operator-rhel8@sha256:afa0b44ce77545a1fc105b9d0c8b5f1eef715e2f9491f0075bdad4385208f42c_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-operator-rhel8@sha256:f486398c18878a624d12a4d82bf6d72f72447ddbdc5a764a6908674a14efad22_s390x as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-rhel8@sha256:4ac0ffd9db1d6579f0456752f2fca8b686ce1c62578187f4db7c402f0efb89ea_amd64 as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-rhel8@sha256:a5d427872efcf0c350f89cfae291c8ad808f68123eda0b5163496315f04e2779_ppc64le as a component of Red Hat Quay 3.1
- registry.redhat.io/quay/quay-rhel8@sha256:c7bf8d54e019c893484b055de7a2b6938152403cfa4b064054c537fb186998de_s390x as a component of Red Hat Quay 3.1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:33683
- externalhttps://access.redhat.com/security/cve/CVE-2026-10143
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-48526
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_33683.json