Red Hat Security Advisory: Red Hat Quay 3.12.20
🔗 CVE IDs covered (22)
📋 Description
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-32591 — mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint
CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45822 — decode-uri-component: decode-uri-component: Denial of Service via crafted input
CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
🎯 Affected products29
- Red Hat Quay 3.12
- registry.redhat.io/quay/clair-rhel8@sha256:45d4574f48633e9f3c8495dc9301cf9e763f34dcf6a357d6d5cb94ec5e2457b9_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/clair-rhel8@sha256:468142f734967c9b0b4f894b0e085e8b6abc5bfa5e5e2283fa39bab589169adf_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/clair-rhel8@sha256:4db81a2e6fabf71b0b149e91cb75048f1898a58d3e494ce640c4815374342c86_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/clair-rhel8@sha256:aec2352526422a9254171e5315c7c9de030473565a90008c8ca4a512acfc7ad1_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:2ceea217c5db3618477887fbaa03e8f8c50c12192490fa59141c7e53cc020601_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:1f36419d267f0ebf8cfe2bc44b39310dffa4a6a76797325def110d659ddad569_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:5bd43bf7fc303c4a17b701d76b7af74e02626692b364bd2ee203a9c0040a2b38_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:d8faf0239f64f26c540ce37c07cc0a60fca0714820f9a7d18962efe7e29c0591_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:dc2972f26626a1492d1294c791f4446b9357a0b905efdff753d14b5a606f0f10_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:4867f2014f183d9113320d7ac32ff75f0eeae74a8a70f23e85c71bce7308b789_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-rhel8@sha256:058a23bd8c03725bc20e1a9c14bbb8703c4d8ed048e6e7e73d801d30855d22d8_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-rhel8@sha256:35d52a9b80c2fe7ce44c0432f6978c46221481c2564c57e52a13bc641aea6c40_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-rhel8@sha256:86b37be69324dbf1ff1cbb6466cc4af1af1e447f95bd92c3fed291228869e3ab_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-rhel8@sha256:dc823f4e764ea5849a3f7a9f13e87aea9126fe71e71edf6e2eb66641b7099c3d_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:007e613b5b6b22468ad411bb6c86b2746c5a32940edec08d9eb4e921464a7fff_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:881c3b07135e3b58a87dd594f5938a2125031cdf646152362882ec62a4c4376c_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:8f4894e944ec2632c815f9d5e342aadeb6b3a3755f12f1398936af8b769f099c_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:c3a0eb125dbce20eba957cab3865e6315eb8a33048073f69e7e1ec1869deec5c_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:fe72115213b1439fa0d309b915276f711c5722cbbfc36a17c121b5cff7420a19_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-bundle@sha256:eeb44c917a431bf0aa7767ae5fc91f11dd81ee0ee3e520ad75e2b8e173bcf070_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-rhel8@sha256:30f9fbbeced4531778c57025b196034a030b67d7b974ffd429e006684b90393c_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-rhel8@sha256:a661e9a46ab33f04a7036faa3a395050cc74fd37a1fbd828fa6a781698f40a22_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-rhel8@sha256:ba7fa3bc25063653e47bffa117978b1eb8a29a6941e5556ebc579c5b6d46ddcd_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-rhel8@sha256:e74476a507c77f2bf58149dc90b564d868da097e2d92b2abebb2f60f1fd0dd5e_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-rhel8@sha256:66afc63628c46fd5487f36bbad8832c6acf8e7da6b28b826b618a3fd8086fd90_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-rhel8@sha256:a1447de1fcb5899d43d7598e2bd25e089c08b5d204ca1ffd8bfef1a85044c76c_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-rhel8@sha256:a91dc54908b3c6f6fad385060c208942634f4989518a711c62958317cb4f3bbd_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-rhel8@sha256:c766e6c1f1947d1baf8cb2b02dea6f50606858e78405e465e8decd2f5eabbbf8_arm64 as a component of Red Hat Quay 3.12
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Validate and limit the length of any user-controlled input before passing it to decode-uri-component's decode() function. Inputs containing more than approximately 200 percent-encoded tokens (e.g. '%ab' sequences) can trigger noticeable delays. Reject or truncate URI components exceeding a reasonable length threshold before decoding. A fix exists in the upstream repository (commit fa479daf) but has not yet been included in an npm release.
🔗 References (25)
- selfhttps://access.redhat.com/errata/RHSA-2026:43052
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-32591
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45822
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_43052.json