Red Hat Security Advisory: Red Hat Quay 3.17.4
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-15927 — quay: mirror-registry: SSRF: repo-level mirror accepts external_reference without URL validation CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
🎯 Affected products32
- Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:49a2e8856100fa93a933746580ed5a9cb1418fac17d0557a3a0ee0be98576261_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:96d1f104d0e0b5b2ac79029baf3d41e8490cc0f7b96792049a443ea27f5dfc15_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:c3c71d300d5d2ae451be96180405aec9a5afd1ef2b48099a1eb53a46b2548618_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:d3601d847460c5023736da87f9d1aec44ff7a5b311f731a1818573a5ab82e966_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:f2de392852cbbd74d59a07a2bdd91030c563b65f694cb23845da4a8ae198c0c4_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:17f37ac6f59685f0d332c970ee33d025cbe834f0f2ed684feee1d6084b7ef5fd_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:345fce838fb057d96437df0c30bbbb90d4dec0d19fcd4ced8b11997adcbb0a89_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:672e6fbf2da879bdfd80798e36b69466329cf8de70f61be88b0f4ec0ebaf2eb6_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:c9871813ad1fa8410cd1954e7c16a6e939edca036be40df4b2117d1595bb6236_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:5444661ed0a7f4d6cf943bb7465bd7c75918e1c2fc159fe341b1b7044ac320b6_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:723c7f83145d5b5c9a30154ee9bfd70f55144d643c15e17f1f5a1db16c317d98_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:b6ba88e17383136cab3653b5bd2f7aeaea55f3a67d49e15f3610cdcbda751984_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:bc1a330c680516b4ab6831ce434f5d4158897fa3d632a287872f0fb47e4e5372_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:2b491bdad3973b56ec2c8198003788f8d46d1b2e882885155922bd750814b7e9_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:74edfcc5c7906b3cf16ab02b04eadc8633c7ae1870209a05aa7c6d8836dc3f15_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:857003bf4a8d7de0fa1ac6e1b93b8264161daacb2f7101f6edcc99d8c0eb730c_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:bb4045f0222d4313f6a66b68bc69eb7ec000a4f820c2ca39bb84fde5d0ef45f9_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:2c80074a85868ebbc3070868904dd35fd0c6e383f790915078f34c0a877987b5_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:19af2dbe8723373c8c231113aeab3fe46011c309cac2c6a938956274155e0923_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:730f609c5e53134320ca35b1dac4a87a2d042df313353df1640752576088769b_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:da241413377b6786f210017bdb38e83aa6d7323aae3e896cc9db1f06cc6eb62f_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:f99cdde780614d394510e9e8f9a74321defe5615ce2201c1d6c1ff60567927ac_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-bundle@sha256:e669e36a1e791d1b2751552b4c1cbffee0d95d3e2ccf2cffbd7c653b219795cc_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:32b9fd5174dbb720b470897f9caa708bac8a50a092f517e460f15e2ad8752882_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:50565a29d0257697b3680a2b154c639acd75b1444cedda943628eb009123559e_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:714e5d16549a8290157ed18b97441f960c72ba144d75a705e4b92f458e01a12a_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:a827ed743197c3726f8113156e721edf290574ee982d9349da1a7fa2aa93592c_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-rhel9@sha256:0fdb2561f63f680abdb2cdb52509ebda25cc8ecdb4ef09599c75bdaa4480a46a_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-rhel9@sha256:2f193ba7ede425c34d95c31a3c0c28e7ca6e1d9b07a09f8d4af5218dadae369d_amd64 as a component of Red Hat Quay 3.17
- +2 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict network egress from Quay mirror worker pods/containers using network policies or firewall rules to block access to internal network ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and cloud metadata endpoints (169.254.169.254, metadata.google.internal). Limit repository creation and admin privileges to trusted users via Quay's RBAC configuration. If repository-level mirroring is not required, disable the feature or restrict access to the mirror API endpoints through a reverse proxy. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:54395
- externalhttps://access.redhat.com/security/cve/CVE-2026-15927
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54395.json