RHSA-2026:65514HighCVSS 8.2

Red Hat Security Advisory: Red Hat Quay 3.9.26

Published
September 8, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (24)

📋 Description

CVE-2026-15792 — github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request CVE-2026-16221 — fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency CVE-2026-18255 — quay: quay: Global read-only superuser can view robot account tokens CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-49477 — soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results

🎯 Affected products23

  • Red Hat Quay 3.9
  • registry.redhat.io/quay/clair-rhel8@sha256:778ddeecda231c33be1c5b7be4a7ab89ded6c52c2fb1defaea02344e125be586_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/clair-rhel8@sha256:8f8853a82aa13fc780853cb603178bf37cb9ec2ff5fcdb20c991c36248d2d1e5_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/clair-rhel8@sha256:d8c199d1126dfbf14f28f59019aa07186b9ab317eaec068b6baaa9986fc328c2_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:735e8d045b753f0c5692ac6eda7505f411715b7554c04cff1617bbca4bccfbfc_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:1233e29cded6ff70de2b3241f4367c4dd04a52ea5ed0cc9ea3fa921e87fd621d_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:4c1c63a4c1b67a5d78ec554a7a5d7887b58bc9f1440d40555838a46e943c9d34_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:f57146e3ebfdcb141f29729130c9abe300cb07d826f9ad88fea6482ea64e4245_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:cfad760d853381eab84fb09c58bd867a2f6e8e32d67d183a870dcdec3967007d_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:2d50aca337a0ce8273980219e243aa689bbd127d51dd0ce6efc0b72e08168306_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:38d3fcb89a38eaa759c5388ce80ec7653ae4522e1ebc6ccfd59582f7d67677ac_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:f951c12ea99f1e84136874a3f321a0f972bad1ec2944fa9265b25485e1adebf6_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:bfd098013eee11a83299eb9d533458dcf918ae1e3e59cb8c3fcc887784104b9f_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:28d2b08f1fc08046115c88fe9ffd2879f9b2898586038297661e3aa20ec5feca_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:535e4c4c61354de56e5c39c6048674f9e74ad1cca65c4199b135b9f50f25c345_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:70264205b43c724ad5ab45e3e88341a463df2a52f6cadd72b226ecac2aa21383_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-operator-bundle@sha256:dfeb8013b678cdbdbde22380a9e94c0c5a4b535228ca6061fd59495df0e4e3d1_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:0c397a0db8ba03e513b09a7de85861ceb217ed6fa85232844541cbae05d4ce2c_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:78474eef20360703105f831266a83e56539cf475761eb0087e700d26d639b9fd_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:8da02a7a888055037d8b46fcbe99ecb11a40dc2aee8c0dd6ad74a4069de20863_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-rhel8@sha256:216b1b129c1a34c0aef941036d01b89f978ed9efe679d6340f763310add54371_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-rhel8@sha256:83040da0106d8351e7c78aef48c0b60891f452373374412503a4339a45ef0a97_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-rhel8@sha256:9cd647ee1283b1ae146291856a1e8bbea85e0309daac2e04eadd506ed70795bc_s390x as a component of Red Hat Quay 3.9

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Avoid building container images using BuildKit frontends from untrusted sources. A BuildKit frontend is typically specified using a "# syntax" directive at the top of a Dockerfile, or with the "--frontend" option to the "buildctl build" command. Only use frontend images that come from a trusted source. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Remove users who can not be trusted with robot account credentials from GLOBAL_READONLY_SUPER_USERS. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources.

🔗 References (27)