RHSA-2026:42796HighCVSS 8.8

Red Hat Security Advisory: Red Hat Quay 3.15.6

Published
July 21, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (28)

📋 Description

CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-10143 — kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-32591 — mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens

🎯 Affected products23

  • Red Hat Quay 3.15
  • registry.redhat.io/quay/clair-rhel8@sha256:15683251d1fa746a06d2a00229341786e8c30abc3ea0524bce5bd0e9c63f35a4_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/clair-rhel8@sha256:8ef6aeb844ef1b27f6229e43eb40730cec60d1f526d591092ee8c87a1628a0f0_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/clair-rhel8@sha256:bdda83a73678d83ee2db6aeebb62ae958c510ddc6c9e2046b1eaf42a89d37f7c_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:4c927a525d6fd7d6aa6b373ff4396804c62a045aa118d556b0c6c9dfea41da82_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:025242f9cb11c9fda5f7b2aa4684e7a2c32a576bff585b2e44f72b6c92fe8bfd_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:ce5cb95162f088a8726780b2a7185030ee10cc5e24ae836d13be53d8180ec974_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:e328c7c06d260a6b926830c78ce72b527e1f414b6e7e339e8418997dce4ad3af_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:46c0ebdf3f1992ae4a517f5d23e56e59c2dd86521c0304a3413b761ba6097041_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:5a920f1ee3582f2363e19252ba095b6890729409f8d46b6996901b6b3413f665_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:71930a5bb5582a0c09c3ccdb653b409178bf1f6b9bef69077c1ac3cfa990246d_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:77d5045a39f4004c8ba16ffd2b2c5afbfaab520958267fcaa79fa5683883f0a6_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:b42d71f71cddeee129d99c9eed21f4dc136a66b9a25f5254df3ed8102fbdd038_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:93132f0d217b876d04309a20f5db54028b85cb6f973e90991510f733d4d89d00_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:934518eecd9771a5daa7dcd32b4d7afb581f7f44664f8055a2515d6ca732b004_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:f6839afafbfd659412968f5482191d9e1042454e5131e0903060563899981581_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-operator-bundle@sha256:ab26919a782fccd8e67b91775367c4296f6a47ca524a4246b49ed63b0aa14452_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:5a0f50cd11db2e119d2cbdfbe517a02cf2d3910585e49f1cd2ff996829ff9d33_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:7b33b511fc8fbfbaf9054ef7c76b1c9ba6575b8c876aaa4f3f4c6321aa3b8011_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:efcaaa625ebc59d50a89105069e1e51f5ec93a1090e0b151c98418b604fc3f7a_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-rhel8@sha256:3dbea8c2d897f53fde0d1bfd29732b4353d706349a7b3df2953a6f47e5decfe1_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-rhel8@sha256:55b4f383ce78ceddb4e979cc892daa9e9f325ea21926f4bdea95918bf6194d98_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-rhel8@sha256:6c72e83568757192c6b755ee4f8051104825e467b6343b096caf551b75dedd46_ppc64le as a component of Red Hat Quay 3.15

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect.

🔗 References (31)