RHSA-2026:63307HighCVSS 8.2

Red Hat Security Advisory: Red Hat Quay 3.15.8

Published
September 3, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2026-15927 — quay: mirror-registry: SSRF: repo-level mirror accepts external_reference without URL validation CVE-2026-18255 — quay: quay: Global read-only superuser can view robot account tokens CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-49477 — soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results

🎯 Affected products23

  • Red Hat Quay 3.15
  • registry.redhat.io/quay/clair-rhel8@sha256:483abfcbdfd29453ec86bf7ce858a75abb4eaf70eedcd63a67484364ec831aed_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/clair-rhel8@sha256:76e67fa13972a0a301849cf0f6934701cc149e235341ddf51a59401da16dfb18_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/clair-rhel8@sha256:a7991a3736f7bf4071f76a4dc7c1099b1a879ee344c7fdf24e6bd02e7d7f2d82_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:26f2c35032f706fedeb90e7747c7d5c38582f898d30e353711420df82dd86978_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:8c37bedbf4a0a0970d9a962c5b6fc8fd610975e2cdc44b470f986db00dd890d1_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:ebbfc055d4e7d306cc31961fa0082bbaece26362d671dab06bf947de9ab86abe_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:f744a688215a5826bcd0f64a2418277d9017866f9f9a284a1451a72a0a1b0f05_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:79e2c8a18682cf8a7126145600446a186752a4abf1972b7f122c7533cbdcafb5_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:0b3bfd2452eae566214670d4e08e554b58e270d2be3a5c0c0ce55184fe2d26ee_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:cb02d5a909d3ecb2b819c8e20d5a49e06d26e99876286b93b635e481fcf0e18d_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:d1c6c4fc0cb17637608e9218b47e1aab92d1672b839f18f33737ac5657fd78ae_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:70b8735da066da874f7c4b9e2d98e70766ed897f1d9bd49ed444e015b1e4b66f_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:e67f07891d3c3e3e28bd803277eaa10ce2e1af349487a386fbe4b7896931c1e3_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:f4a583578a3489a6f723ac9619f709fb1ba33b90af365eaee88984cdd1036e8e_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:f97ffce4325909ad1eace0fccf0d3f3f85782f4a0b2b042fb2f85775a302af48_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-operator-bundle@sha256:1d1de1b252cd2449d042ec63292537f5fe74ffdee3c7dfe23c01516009147161_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:162f7e5aa6ee7237dec06945d3d2aae55009a352d73856b5de7b262f57e3024b_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:38b5bc6606276ffc743d2bada43026d44556bf312cfed4470d4625084fee60ce_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:a16b07e4d12738efac798f505452f0b3866ff8d93673c8c5af95beafee83d665_s390x as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-rhel8@sha256:64967e93bbf7f56601309bea7951c40c2b9fd01be85324d5287c20bf5083861a_ppc64le as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-rhel8@sha256:8d540b5a0cbe5db8b35ec6b3de676e30bafc9f96dd84298fa0f940d89d372a01_amd64 as a component of Red Hat Quay 3.15
  • registry.redhat.io/quay/quay-rhel8@sha256:fbfed57fbd3387c4066ef25d30f098632c8ccf9c75e6c37fbfc4b1b79c934998_s390x as a component of Red Hat Quay 3.15

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict network egress from Quay mirror worker pods/containers using network policies or firewall rules to block access to internal network ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and cloud metadata endpoints (169.254.169.254, metadata.google.internal). Limit repository creation and admin privileges to trusted users via Quay's RBAC configuration. If repository-level mirroring is not required, disable the feature or restrict access to the mirror API endpoints through a reverse proxy. Workaround: Remove users who can not be trusted with robot account credentials from GLOBAL_READONLY_SUPER_USERS. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.

🔗 References (14)