RHSA-2026:48085HighCVSS 9.1

Red Hat Security Advisory: Red Hat Quay 3.18.0

Published
July 29, 2026
Last Modified
August 21, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2026-4427 — github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message CVE-2026-27459 — pyOpenSSL: DTLS cookie callback buffer overflow CVE-2026-27962 — authlib: Authlib: Authentication bypass due to JWK Header Injection vulnerability CVE-2026-29074 — svgo: SVGO: Denial of Service via XML entity expansion CVE-2026-32590 — mirror-registry: remote code execution using pickle deserialization CVE-2026-32591 — mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data CVE-2026-48526 — python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens

🎯 Affected products32

  • Red Hat Quay 3.18
  • registry.redhat.io/quay/clair-rhel9@sha256:8e4ba7b36bb00f85351969db32a69ad53c0a830bd28e99d52c634957d0116872_amd64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/clair-rhel9@sha256:a3f7e751e73a721c9f5d430695db34ca46220c77e2c4a405f289b69971032768_s390x as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/clair-rhel9@sha256:bde2614ef2445a23f8261dd0547d4b8b6dc1729166feb2205013f69e02e8a0f0_arm64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/clair-rhel9@sha256:c5e4e4beecb97e537bfc5c3625ed44700d76e76b4255c42a1a58eba17dad3ec1_ppc64le as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:188197a713a80ad9157543603ab4a9a2dd3b1ac02dc88e09769e02cc03f53226_amd64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:12843e40f6259e2cadb64f523b6a90cfdbae1bc9a7d403febaf4843988e5824e_arm64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:4d11b17e949e0a60d5f1286de138b7f1972bb171339d3a1025a611e34d2e3b97_s390x as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:965399c975124f57adaa95dedad69dc5a55ba9a3f0c1149c48a9a1c4a0236d9a_amd64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:f720ee9b9001f3e5247f23bd379cd71dcecb97b1d0ba7408c18e17bd90963dbc_ppc64le as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:0542c1b9d7d04512224735ab114aa5eb032ef8bf1f4d56bb09dd8ec67a563056_arm64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:162d06a526247c2f65c3468aa42734589dedefcd05bccaf49bc94a2df3da3385_ppc64le as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:58b01cbfc532ee3739e53223598d02441259b0552494dd3eda3acdd9daf18681_s390x as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:884f75efc59178b36ea2c03bfbe880f32a7ad9470444dffb5bbb43ccdbc46569_amd64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:71d3d0fa46bca36980ca506eae705b120d9530134dc899b33acf0609459a95ab_arm64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:da29edba778acb7f7fd42408d954363657b6ee33b30234c083f266efc47cb726_amd64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:ef959a28d20634cd659dffbb788bfc08b17f22c1f865746e3114d14cffd163b7_ppc64le as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:fd85bcfac47614fe448ba6fd5020cc01900ce1dbdda2b7ebb37c202dc5f272a1_s390x as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:6840404e712485db83fbfba9117eae50cf64c2a944eb58130c4455e138fa36ad_amd64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:4f72b7b5cbe21d3a45e6da097e107376e16e1e189936ccb63b01c4070e943ebe_s390x as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:62b71ff5b1a1ea65a758f7ad4d2159914370ca98e363c8cadd522dba4228c486_arm64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:e07a70ef05b6d254743e387e391e56942beb34968348277ff1e79c2a56ead6af_amd64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:f2be30c6ab2d3f5f0c7efe4fe3b078b4d4312d6f948464c6331f36825fc44a8c_ppc64le as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-operator-bundle@sha256:030ee454a0e8ae48d1c934128f554ff0b83afe1ca1803cdedfc14bb28a62d019_amd64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:4edc046a5e57b80baf5df567f04785799af859b56c187f0614ca1e97fc1490bd_ppc64le as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:7a80ffaa13fdbe5a30f8827b454d5b67814724a473370dc0d9d5192c3801f304_s390x as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:bc606a6e09b2f435906e583ab20dacaecee704da54195befd40f9cfa40ab0ff1_arm64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:f71061cdc7d305b4589266f1833b2d0d2108cfb86be27d0fddb19dea8835cfb0_amd64 as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-rhel9@sha256:14e7fd727c1dc74e19001952176a8354cbc97ec5b4643a4815b6ffbc6d76e224_s390x as a component of Red Hat Quay 3.18
  • registry.redhat.io/quay/quay-rhel9@sha256:4207ba218f8ae31531add66d3ef5bf726f0034dfa7abb109d2c1bb1e2ed8b95b_ppc64le as a component of Red Hat Quay 3.18
  • +2 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this flaw, ensure the callback provided to the set_cookie_generate_callback function strictly limits the returned cookie string or byte sequence to under 256 bytes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (12)