Red Hat Security Advisory: Red Hat Quay 3.17.4
🔗 CVE IDs covered (32)
📋 Description
CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
CVE-2026-10143 — kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
CVE-2026-15927 — quay: mirror-registry: SSRF: repo-level mirror accepts external_reference without URL validation
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-44432 — urllib3: urllib3: Denial of Service due to excessive HTTP response decompression
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-54058 — Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image
CVE-2026-54060 — python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files
CVE-2026-55379 — python-pillow: Pillow: Denial of Service via crafted BDF font file
CVE-2026-55380 — python-pillow: Pillow: Denial of Service via crafted GD 2.x image file
CVE-2026-57231 — podman: Podman: Information disclosure via malicious container image environment variables
CVE-2026-59197 — Pillow: Pillow: Native heap out-of-bounds write
CVE-2026-59199 — Pillow: Pillow: Denial of Service via out-of-bounds write in image processing
CVE-2026-59200 — Pillow: Pillow: Denial of service via crafted PDF stream
CVE-2026-59204 — Pillow: Pillow: Denial of Service via crafted JPEG2000 image
CVE-2026-59205 — Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
CVE-2026-59885 — pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER
CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values
CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow
🎯 Affected products32
- Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:49a2e8856100fa93a933746580ed5a9cb1418fac17d0557a3a0ee0be98576261_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:96d1f104d0e0b5b2ac79029baf3d41e8490cc0f7b96792049a443ea27f5dfc15_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:c3c71d300d5d2ae451be96180405aec9a5afd1ef2b48099a1eb53a46b2548618_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:d3601d847460c5023736da87f9d1aec44ff7a5b311f731a1818573a5ab82e966_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:f2de392852cbbd74d59a07a2bdd91030c563b65f694cb23845da4a8ae198c0c4_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:17f37ac6f59685f0d332c970ee33d025cbe834f0f2ed684feee1d6084b7ef5fd_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:345fce838fb057d96437df0c30bbbb90d4dec0d19fcd4ced8b11997adcbb0a89_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:672e6fbf2da879bdfd80798e36b69466329cf8de70f61be88b0f4ec0ebaf2eb6_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:c9871813ad1fa8410cd1954e7c16a6e939edca036be40df4b2117d1595bb6236_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:5444661ed0a7f4d6cf943bb7465bd7c75918e1c2fc159fe341b1b7044ac320b6_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:723c7f83145d5b5c9a30154ee9bfd70f55144d643c15e17f1f5a1db16c317d98_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:b6ba88e17383136cab3653b5bd2f7aeaea55f3a67d49e15f3610cdcbda751984_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:bc1a330c680516b4ab6831ce434f5d4158897fa3d632a287872f0fb47e4e5372_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:2b491bdad3973b56ec2c8198003788f8d46d1b2e882885155922bd750814b7e9_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:74edfcc5c7906b3cf16ab02b04eadc8633c7ae1870209a05aa7c6d8836dc3f15_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:857003bf4a8d7de0fa1ac6e1b93b8264161daacb2f7101f6edcc99d8c0eb730c_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:bb4045f0222d4313f6a66b68bc69eb7ec000a4f820c2ca39bb84fde5d0ef45f9_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:2c80074a85868ebbc3070868904dd35fd0c6e383f790915078f34c0a877987b5_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:19af2dbe8723373c8c231113aeab3fe46011c309cac2c6a938956274155e0923_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:730f609c5e53134320ca35b1dac4a87a2d042df313353df1640752576088769b_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:da241413377b6786f210017bdb38e83aa6d7323aae3e896cc9db1f06cc6eb62f_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:f99cdde780614d394510e9e8f9a74321defe5615ce2201c1d6c1ff60567927ac_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-bundle@sha256:e669e36a1e791d1b2751552b4c1cbffee0d95d3e2ccf2cffbd7c653b219795cc_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:32b9fd5174dbb720b470897f9caa708bac8a50a092f517e460f15e2ad8752882_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:50565a29d0257697b3680a2b154c639acd75b1444cedda943628eb009123559e_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:714e5d16549a8290157ed18b97441f960c72ba144d75a705e4b92f458e01a12a_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:a827ed743197c3726f8113156e721edf290574ee982d9349da1a7fa2aa93592c_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-rhel9@sha256:0fdb2561f63f680abdb2cdb52509ebda25cc8ecdb4ef09599c75bdaa4480a46a_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-rhel9@sha256:2f193ba7ede425c34d95c31a3c0c28e7ca6e1d9b07a09f8d4af5218dadae369d_amd64 as a component of Red Hat Quay 3.17
- +2 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Restrict network egress from Quay mirror worker pods/containers using network policies or firewall rules to block access to internal network ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and cloud metadata endpoints (169.254.169.254, metadata.google.internal). Limit repository creation and admin privileges to trusted users via Quay's RBAC configuration. If repository-level mirroring is not required, disable the feature or restrict access to the mirror API endpoints through a reverse proxy. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Do not load BDF font files from untrusted sources. Applications that only process standard image formats (PNG, JPEG, etc.) and do not use BdfFontFile or ImageFont.load() with BDF files are not affected. Workaround: Avoid processing untrusted GD 2.x image files with PIL.GdImageFile.open(). Use Image.open() instead, which includes decompression bomb protections for supported formats. If GdImageFile must be used, validate the image dimensions before calling load(). Restricting accepted image formats at the application boundary to only those explicitly needed can reduce exposure. Workaround: If the application does not need JPEG2000 support, block .jp2, .j2k, .jpf, and .jpx uploads at the input layer. For services that do process JPEG2000, set memory limits on the process or container (LimitAS= in systemd, or memory limits in Kubernetes/Podman) so a crafted image can only crash the worker, not the whole host. Add automatic restarts (Restart=always in systemd, or container restart policies) so the service recovers from OOM kills without someone having to intervene. Workaround: Most applications using Pillow's color management via profileToProfile() or applyTransform() are not exposed. Only code that calls ImageCmsTransform.apply() directly with a user-controlled output image whose mode does not match the transform can trigger the heap corruption. Audit your code for direct apply() calls to confirm. RHEL builds ship with ASLR, full RELRO/PIE, and FORTIFY_SOURCE by default, making escalation from crash to code execution much harder. For DoS containment, configure automatic service restart (Restart=always in systemd, or container restart policies) so the process recovers without manual intervention. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1 input are at reduced risk. Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion.
🔗 References (35)
- selfhttps://access.redhat.com/errata/RHSA-2026:54395
- externalhttps://access.redhat.com/security/cve/CVE-2026-10143
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-15927
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-44432
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-54058
- externalhttps://access.redhat.com/security/cve/CVE-2026-54060
- externalhttps://access.redhat.com/security/cve/CVE-2026-55379
- externalhttps://access.redhat.com/security/cve/CVE-2026-55380
- externalhttps://access.redhat.com/security/cve/CVE-2026-57231
- externalhttps://access.redhat.com/security/cve/CVE-2026-59197
- externalhttps://access.redhat.com/security/cve/CVE-2026-59199
- externalhttps://access.redhat.com/security/cve/CVE-2026-59200
- externalhttps://access.redhat.com/security/cve/CVE-2026-59204
- externalhttps://access.redhat.com/security/cve/CVE-2026-59205
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59885
- externalhttps://access.redhat.com/security/cve/CVE-2026-59886
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54395.json