RHSA-2026:66084HighCVSS 8.2

Red Hat Security Advisory: Red Hat Quay 3.10.26

Published
September 9, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (24)

📋 Description

CVE-2026-15792 — github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request CVE-2026-18255 — quay: quay: Global read-only superuser can view robot account tokens CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-49477 — soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing

🎯 Affected products23

  • Red Hat Quay 3.10
  • registry.redhat.io/quay/clair-rhel8@sha256:5e2faac1e55fe896021b3ebddd1a4191344c51cfdbe1fb3e0e24e30f3afbec8e_ppc64le as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/clair-rhel8@sha256:6566b22902f4ccff34539ecef9a8cc219518c37ee62c35d3aadd7d216d836bb4_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/clair-rhel8@sha256:757451ca9306797387186cd521219dbbeab992cd3d1cd6851169949349fd4605_s390x as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:0c14b0d72bb7596bd17e2203248e1f0188f86cd0c78d6e54a5302ad04d07b912_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:0b692deab8a389d2bd62d560c8c48a3243b64123709c2d8e1d655dd6522ad854_s390x as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:3a870cc5e6519f1016b54980b2bc3426bd76c6d8fefdc6257caa56ec0ae193a0_ppc64le as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:ab5cdec61b95d029afd55c1fe879b0d709698cd31d48887302286fb39eec4fcd_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:6234f20f00a0be8cb7b6e9bbff4dbf0232187c199bc780ed6fd8db9a124c680f_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:6b9c307245ca0dbd2b197fae4a257656d9c4240af72dc319a1ab23b16485ae4b_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:9c7c898f5d52c65e6cae15f066a6023ee0b2deaa4e48e4cf6d4a7227b77bfff6_s390x as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:e597d56199d73791add209adb706fbfb13a69f987fbcc5b441d50743613f2c41_ppc64le as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:57eab4f5090e2733edee91465f04e43502976350a9ac0d0725daad1a19b9199b_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:01b25216bcc4c06361e1865e2967b495fc208b364ed5c302d97e7843704a11ab_ppc64le as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:cf710f889006ca957961aa95c5fa138366e772270d13350926f25c6c9c880bd3_s390x as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:fa587850d6131e139e6d566b4b6a56a56e51984e8c7aac98700176472c6050d1_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-operator-bundle@sha256:777b72c01ebf3b12fac693e8c92782034e3d02fe67447ac679b58d12da91c199_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:05ffa1527e1591bffca6be29b43decd18e7706b8ad5f5886ed9c5d8763bfcc26_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:b3e0e69234e3baf556c2c2fdf4c61c6fa9acbd39f7ac0d60533416ea66ef3ad6_ppc64le as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:ef8507e44d719396e2d1dd699b055cb0ddf8fde2283c011ab5b9e595826f6bac_s390x as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-rhel8@sha256:5d44da098d35821c45027e74ba3be1058249e403b7bb69c94a5d2df2a2018983_ppc64le as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-rhel8@sha256:a8a3d282f314cab61a10bf9f57f1b79627b2048a16e0b8fc1ce437c06f1f5fb0_amd64 as a component of Red Hat Quay 3.10
  • registry.redhat.io/quay/quay-rhel8@sha256:db5d78395e972d6e711b457a4cf4258efe66aa79e5fa73c6a8ac24cb26946cdb_s390x as a component of Red Hat Quay 3.10

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Avoid building container images using BuildKit frontends from untrusted sources. A BuildKit frontend is typically specified using a "# syntax" directive at the top of a Dockerfile, or with the "--frontend" option to the "buildctl build" command. Only use frontend images that come from a trusted source. Workaround: Remove users who can not be trusted with robot account credentials from GLOBAL_READONLY_SUPER_USERS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources.

🔗 References (27)