RHSA-2026:42146HighCVSS 8.8

Red Hat Security Advisory: Red Hat Quay 3.12.20

Published
July 20, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-32591 — mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass CVE-2026-45822 — decode-uri-component: decode-uri-component: Denial of Service via crafted input CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs

🎯 Affected products29

  • Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:18a8f8eb323f7a2e990f5ba912b811d849f849bcc83071f9c75fe3e098061692_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:77d5ecc1ec1ac3f389c7dc947fc92fb029532092464a8ced163669a98557eab9_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:a4433acd91b173767e01d34d19f78ef3af6a9b88f2b637ea3cd822961468d746_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:a72cdc3046f1def5c3b271735acff076135f4cae6e7ee4d7e84f99674d812918_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:d5e108eaf669ea96ca91ce3ed1795da34a35b57d395ee755fce03168b5baecf9_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:25eed7620e576911a847daa544ed2da922a9b6abec2110ff00dc8f76053cc651_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:5bc28abfb9d2c4fce4e6db44adb3a1c15c1e34569a7dc9af3aa140fde4065c81_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:c5eddb56ff26a440621613bcc32c18a4aea37e90e22a2fd034c6c65277ae2fc5_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:f17d9058f34f22f2005d7843569ce4c1a7a5a987a63ec0de0a0e57dcda104948_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:bf5c308db195d42cb056a969ea44953e1b651138858ee525a02ab8536ff043c0_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:75f847501bab8f8c64ca89a05b07871773b3e22567a2aa721631cfc88de8ecfe_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:9acf019723b565f43c7168510556f16fbcb478ad3a00780f3e887bc915d8f363_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:a91fd07e0b3fa39a2858ab1a22e3aad3cfa51d09dec016dce9f9c2b6de83bfa3_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:ab173618612aa2af81e291cb5402311b32da66cfca02da8a016b41b8d4ad6eaa_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:555002449f4047e356874300069b4364498572151a0f537705f13d4b33f311d8_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:8ea3121fa7e3903d54b99f8533a8652b7da7817d1463f29e79df7c7458c915b6_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:9d0a7e1116618faed0d326d51dac00214710b6402a692c28bd310cb3f30a0a13_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:a3719ef849b393b67846d1ff5f1b36c107c9de6ca7d2db7260a26fed45d95416_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:e66901f29aeab09d4f771c122bdd3ac5dd4f4d6e6533abf469ae77d53a9fa902_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-bundle@sha256:708d3814377d64f81094f9b947227fd051da089ce8e9bee1c723b99f160b572e_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:08b9dbff08287097e67f35cf5a1133cc25db5ecbd082cf6a07fd022b88494be6_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:7a083ae6d06472db38914d75014566cda64dbd1022195c37a04d725bb4064f85_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:b8015514cb7e59f0a68465ee42518b370dd6705a1ee2676942f2c45b9903c5f2_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:db891d7c1a8008d8ae07861b1e3999ffb3cb59696b0663cbd20576674dfab369_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:162dc1b0d8928ffde855c5fa7c30363a74ded075e9f7fd6ac1311c92dad8f170_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:60369b0688c7ff80bf3983a232cc25cdb3545a3dc14aef32584f64a2eced3801_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:6921b5638d8c1db4593ca7fece92f035bceb9fdeeb591f7f2421f1f1da6b65f2_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:f6ac4bd92907364b9c637a0314783f671066b017c167696a7683e7c85433ccf6_ppc64le as a component of Red Hat Quay 3.12

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Validate and limit the length of any user-controlled input before passing it to decode-uri-component's decode() function. Inputs containing more than approximately 200 percent-encoded tokens (e.g. '%ab' sequences) can trigger noticeable delays. Reject or truncate URI components exceeding a reasonable length threshold before decoding. A fix exists in the upstream repository (commit fa479daf) but has not yet been included in an npm release.

🔗 References (25)