Red Hat Security Advisory: Red Hat Quay 3.9.24
🔗 CVE IDs covered (24)
📋 Description
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
CVE-2026-32591 — mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint
CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45822 — decode-uri-component: decode-uri-component: Denial of Service via crafted input
CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
🎯 Affected products23
- Red Hat Quay 3.9
- registry.redhat.io/quay/clair-rhel8@sha256:381f3af2c038cb3a0d14191c1a541cc7e9752698ed3980dcd33ee91ef3752517_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/clair-rhel8@sha256:70cf72dcdc1e02b7c7958673e95b92503354c5e5475a1e4fc7ae0f5d3c03fbe0_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/clair-rhel8@sha256:e7eeb4f9684e32f8199b792630e21f9f13e5efe7a511664d5777dc1a98fc4207_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:cac2255c18f3a8d7e67308b07ea5b3ba0317cf2e2911321b9cc4fba45c4b2583_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:3994488939804e50e226f273722d2ad3f3b6aaee6c70e52752cbc8affc36bc52_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:54cfdc97172ce2c4cef1c85b5187c3401aee0e1ba272977d099e12f59d5d4d05_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:6bd95b42094007001481b27000ead5c252747f1a79fcf0801030593de163ffaf_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:8f4be0a96b74ebe660bd28e9cc15ef9cc56428532fae4ad0f04562726dcc7226_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-builder-rhel8@sha256:6bdc4472dea000261ce7aa6daa850f5e1253ba716de2a247df997aaf158cf20f_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-builder-rhel8@sha256:b6109a8cab187a42f5f9f536fba1be506474eb532ad41d68f937606318e88364_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-builder-rhel8@sha256:fdec2d2556842d4c6cd4feb37243580c6323f16813754aaf02963ba1a23b7e96_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:9f2a14e20042280f51bfec86c00ac87a5309c991efc1b8b6f1dd0afb7772c297_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:ae9ba588f153ed4ad2e34936867f435cc8271b2858b00c3ce823a773c640a4f6_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:c51a3f7d6fc2ea1c26ba1ccfaec660d6f76cb3e656f3d1c0702d14338ded96c8_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:e4fcfcd95a0db4d1da19ba16146c51237c83129719c5550977391f2978e62ef3_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-operator-bundle@sha256:2af202af0c417c0b1bebf895cd46b15d4c6daceba48a11217f7c574a01ef5aa0_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-operator-rhel8@sha256:041665ae3ee470107c533393bdf77143d70d020d4670b73b890cbe7794401f62_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-operator-rhel8@sha256:25009b47369d945141850084b0f2f303e72e8137b547de01c7b79c66141a4ad8_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-operator-rhel8@sha256:855d3b6c7ca77ef02aaa029c45e003c80ad9e1f8bd61a7d244ff475b26e6cd98_s390x as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-rhel8@sha256:4732513293f2df546416fc805ea717f2b211ebe0fc5a16d8fd2c78c24ad79eba_ppc64le as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-rhel8@sha256:c9f851e253fca208fc6dfe8ce468824ae99dfdeb1f9cfe8cb47706a64562701e_amd64 as a component of Red Hat Quay 3.9
- registry.redhat.io/quay/quay-rhel8@sha256:f8a741914232bb80b1b3a542ad0ba3392593b4c8f9018a63f11380afdd19ceca_s390x as a component of Red Hat Quay 3.9
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Validate and limit the length of any user-controlled input before passing it to decode-uri-component's decode() function. Inputs containing more than approximately 200 percent-encoded tokens (e.g. '%ab' sequences) can trigger noticeable delays. Reject or truncate URI components exceeding a reasonable length threshold before decoding. A fix exists in the upstream repository (commit fa479daf) but has not yet been included in an npm release.
🔗 References (27)
- selfhttps://access.redhat.com/errata/RHSA-2026:40262
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-32591
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45822
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40262.json