Red Hat Security Advisory: Red Hat Quay 3.12.22
🔗 CVE IDs covered (23)
📋 Description
CVE-2026-15792 — github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request CVE-2026-18255 — quay: quay: Global read-only superuser can view robot account tokens CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-49477 — soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results
🎯 Affected products29
- Red Hat Quay 3.12
- registry.redhat.io/quay/clair-rhel8@sha256:3d81eed7effff4036b246295fbfbe4f931f20f1d42d9b862a9856228edcf2e98_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/clair-rhel8@sha256:b426db069b9f9d0d989efb38be2cfc47d1dd77840b621d037b3e4ab4f9c5d642_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/clair-rhel8@sha256:b523b4e2db568a8ea211c939c9f61f6859b7647c111e5856c89ac3431c0d4079_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/clair-rhel8@sha256:c5b6c68680848ad841793d2042692402c973311512019207c99e81a76b872626_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:4f07b87973fdd00d37f50b7dc944386f8ce7a072ede1b5500d0dfe4035575a7c_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:004b4b6dd501b1ac0b929f01c6b9572af2badd8b89c5421ccc233f6578df0956_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:083fe19df23e831da85b4615d05b95abb1eba3381f71138c6b680d7a80f446d7_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:1622b016403abf3488feb888932cf066ef1dee58cea59c42efcb056f00c7d3f4_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:25f2e06585a69804e64a9af719c886a8c9270ae91aeb41202d33e60e45e9e6aa_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:85e26d043c96ff512c781c0677f4948584ca662a5ceb62562a98b2f38932e2cd_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-rhel8@sha256:d427ebb49afb3b8c9cc742cae00912bfbd9cde2c97f78d5596415e5fb2337e59_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-rhel8@sha256:d6af973eef59764218c0decb6faf21d256ddc03b15f47ff321d1cc833ada7289_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-rhel8@sha256:e173af8ad1e038f43395f17c1fe2cd226e1bf6f70813a9148c2520a808d2dd28_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-builder-rhel8@sha256:e3032e0cb5d2e4c7ba132405ca012f95ca05e0d4ec52f2c310cc635a23a42cbe_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:bc431b10367e483c8f6b0a2e9732e9e95f7508afa0e37fe1efe02bb64a013fe6_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:7f25a9c3bd8110ec7b290d90020c1c14c9b80a465d26eba96343deb20a7c43ff_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:8071935d48369d6e1899da8d642b7068440f756bae564a3b9009a80e6d798c1e_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:8b4b3e5ddeb1585e85ffba653e968e260f5a28498a4bca9e7737c337585313b9_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:af3cb853e569252e4d7bda344197335c35fae6f6e6cd1c3a5777c75057ba0f4e_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-bundle@sha256:496a4a6b2462f61bf61f9d0784d3fbf4bde254c9e4bd590cd28f79dfa64deb0c_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-rhel8@sha256:4b0ea5dfaa1cc9adc828d4ce9101f06bacf608deb6eb33ae5cd3bb0b430e1f77_amd64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-rhel8@sha256:672f7efb71ec7e851f0a785a861cb51b38ee51d5d627af45ab6c9afbdef8ac08_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-rhel8@sha256:6aceeed9fb66fcc9d485142591a94e24b6c46ecd31be20f1deaaf87c2ffceb12_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-operator-rhel8@sha256:d7fb3597d6374743e2b03102cb82028d2e6c486d5f17a8184cfd3440d369bdb0_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-rhel8@sha256:17ec4316e8933a1a3939063b888726312670dc3078390737a368971342fc8941_ppc64le as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-rhel8@sha256:48cd7baccc7f6b7f78c25dfef78fa1cbdd3f44f82671c10e92ecd01dc5bfa11e_s390x as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-rhel8@sha256:a049d28ebe1a8c2cbcb3979da403fc6eb8f56f8234d39f5bb705d1680507a579_arm64 as a component of Red Hat Quay 3.12
- registry.redhat.io/quay/quay-rhel8@sha256:b9dab5ca627e180740bc099518a6daaef8bcca091c92d62f8ad9cffb11917e39_amd64 as a component of Red Hat Quay 3.12
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Avoid building container images using BuildKit frontends from untrusted sources. A BuildKit frontend is typically specified using a "# syntax" directive at the top of a Dockerfile, or with the "--frontend" option to the "buildctl build" command. Only use frontend images that come from a trusted source. Workaround: Remove users who can not be trusted with robot account credentials from GLOBAL_READONLY_SUPER_USERS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2026:66523
- externalhttps://access.redhat.com/security/cve/CVE-2026-15792
- externalhttps://access.redhat.com/security/cve/CVE-2026-18255
- externalhttps://access.redhat.com/security/cve/CVE-2026-32283
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-44705
- externalhttps://access.redhat.com/security/cve/CVE-2026-49477
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-67313
- externalhttps://access.redhat.com/security/cve/CVE-2026-67314
- externalhttps://access.redhat.com/security/cve/CVE-2026-67320
- externalhttps://access.redhat.com/security/cve/CVE-2026-67321
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73088
- externalhttps://access.redhat.com/security/cve/CVE-2026-73089
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_66523.json