RHSA-2026:69255HighCVSS 9.1

Red Hat Security Advisory: Red Hat Quay 3.16.6

Published
September 21, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (42)

📋 Description

CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-15792 — github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request CVE-2026-15927 — quay: mirror-registry: SSRF: repo-level mirror accepts external_reference without URL validation CVE-2026-16221 — fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency CVE-2026-18255 — quay: quay: Global read-only superuser can view robot account tokens CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39822 — golang: Go os.Root: Symlink following vulnerability allows directory traversal CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-49477 — soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings CVE-2026-54058 — Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image CVE-2026-54060 — python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files CVE-2026-54770 — webob: WebOb: Open redirect vulnerability leading to phishing and token theft CVE-2026-55379 — python-pillow: Pillow: Denial of Service via crafted BDF font file CVE-2026-55380 — python-pillow: Pillow: Denial of Service via crafted GD 2.x image file CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-57231 — podman: Podman: Information disclosure via malicious container image environment variables CVE-2026-59197 — Pillow: Pillow: Native heap out-of-bounds write CVE-2026-59199 — Pillow: Pillow: Denial of Service via out-of-bounds write in image processing CVE-2026-59200 — Pillow: Pillow: Denial of service via crafted PDF stream CVE-2026-59204 — Pillow: Pillow: Denial of Service via crafted JPEG2000 image CVE-2026-59205 — Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-59885 — pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-75593 — github.com/moby/buildkit: BuildKit: File escape vulnerability allows unauthorized file modification CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing

🎯 Affected products24

  • Red Hat Quay 3.16
  • registry.redhat.io/quay/clair-rhel9@sha256:65aad515df0362df61615bb2daabc49dd4344326e3b1e910dfa58c4657e5d005_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/clair-rhel9@sha256:774609746a94c01ac0c321fb37d6397e9e36472b1a2c74686a6f8f6beff69ca8_s390x as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/clair-rhel9@sha256:fae9bf8bb9619ab76eb8b02f0db54f76dcee4d5d8e3cdfc18e4a1eb6ea53ef00_ppc64le as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:d8b5fa9e65c6812893e4030225fd24ccde1f84db62a058a1702260a6fa976a50_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:246ca687bc07336a7a1f6bd679c61c8854f5ffbcd5ed76a770bc37810b98b744_ppc64le as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:4bacacab1b96616a5e3b036ab87945cbbdad9554425cb6f342bdf1b58a4b2eca_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:71970193f2dbda6d3f39c914e60b2bcf17945d8409f45e0acff56b7e29799815_s390x as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:a6794c937636ee68c8ab53d8fa25556b9039c2ea8da6b166814478b6e329b0e1_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:543cf73accd633a8b86005b83220b3ab249611e433a795d34afb0c891c25bf89_s390x as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:b9ffed2aa8e2041cfb161d8d55c415557bbbcc40b5e76735b01e19acc6f3c850_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-builder-rhel9@sha256:dfbbf0638eb70bd2641cbd1c3d3757c043c1a9780ed5f4c9c109f4bc6293ad67_ppc64le as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:056eaee2e613a95da856a57959825cd41661c671059d8799241712bd0f075888_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:159316f0ad9942ee00f49625e9f55ed1e2e1ceacc6b07062851b53e803d2712a_s390x as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:99718b05907e628bd999499a10b856018d135a3445921916ba9c3749a068220a_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:d2d01db4c955deb5d0704fdb7c4ef9660719bd0f4dd18d0d64f3c788e8836b5f_ppc64le as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-operator-bundle@sha256:39d5a52886d609e675d952784c8f609490ff3f69021f35db7831f6fc9449a573_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:6a5d5f62bd0b0cfe8330e5d685c8e722176e3f254bbe0fad4a1ace064d57700a_s390x as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:98c82825cc0375337fcec210f188eef5d69e44aa676b95404326f9ac3937231a_ppc64le as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-operator-rhel9@sha256:fda11b769a92decfe88ca767ae65586853a5511f221eef92b369017d5284e389_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-rhel9@sha256:87d9fe47faea904645aa6ec202f28765fa9a710d3dfe3ccfeb3ca46b5a5d5d67_arm64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-rhel9@sha256:98016f1125ba118b02aea3467d44f9f71b8dc3f090cfbece5507d51590e08084_s390x as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-rhel9@sha256:c01fdefc968c09f162f5d828afef1a659d7af87f34c42170b0ccaea461ba15e9_amd64 as a component of Red Hat Quay 3.16
  • registry.redhat.io/quay/quay-rhel9@sha256:deee305468e059e9d0e085cdfd5f54041d7a29df675e81b76da41896e55908d9_ppc64le as a component of Red Hat Quay 3.16

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Avoid building container images using BuildKit frontends from untrusted sources. A BuildKit frontend is typically specified using a "# syntax" directive at the top of a Dockerfile, or with the "--frontend" option to the "buildctl build" command. Only use frontend images that come from a trusted source. Workaround: Restrict network egress from Quay mirror worker pods/containers using network policies or firewall rules to block access to internal network ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and cloud metadata endpoints (169.254.169.254, metadata.google.internal). Limit repository creation and admin privileges to trusted users via Quay's RBAC configuration. If repository-level mirroring is not required, disable the feature or restrict access to the mirror API endpoints through a reverse proxy. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Remove users who can not be trusted with robot account credentials from GLOBAL_READONLY_SUPER_USERS. Workaround: There is no mitigation for this issue other than updating the Go toolchain to Go 1.25.12 or Go 1.26.5. Programs compiled with Go >= 1.24 that do not use the os.Root API are not affected by this vulnerability. The os.Root API was introduced in Go 1.24. Go versions prior to 1.24 are not affected. This issue is fixed in Go 1.25.12 and Go 1.26.5. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: Applications utilizing the WebOb library should implement strict validation of redirect target URLs. Configure applications to only allow redirects to trusted, fully-qualified URIs or to strictly allowlist permitted redirect destinations. Reject any redirect target that does not begin with an expected trusted host or a validated relative path, ensuring no leading whitespace or control characters are present. Workaround: Do not load BDF font files from untrusted sources. Applications that only process standard image formats (PNG, JPEG, etc.) and do not use BdfFontFile or ImageFont.load() with BDF files are not affected. Workaround: Avoid processing untrusted GD 2.x image files with PIL.GdImageFile.open(). Use Image.open() instead, which includes decompression bomb protections for supported formats. If GdImageFile must be used, validate the image dimensions before calling load(). Restricting accepted image formats at the application boundary to only those explicitly needed can reduce exposure. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: If the application does not need JPEG2000 support, block .jp2, .j2k, .jpf, and .jpx uploads at the input layer. For services that do process JPEG2000, set memory limits on the process or container (LimitAS= in systemd, or memory limits in Kubernetes/Podman) so a crafted image can only crash the worker, not the whole host. Add automatic restarts (Restart=always in systemd, or container restart policies) so the service recovers from OOM kills without someone having to intervene. Workaround: Most applications using Pillow's color management via profileToProfile() or applyTransform() are not exposed. Only code that calls ImageCmsTransform.apply() directly with a user-controlled output image whose mode does not match the transform can trigger the heap corruption. Audit your code for direct apply() calls to confirm. RHEL builds ship with ASLR, full RELRO/PIE, and FORTIFY_SOURCE by default, making escalation from crash to code execution much harder. For DoS containment, configure automatic service restart (Restart=always in systemd, or container restart policies) so the process recovers without manual intervention. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1 input are at reduced risk. Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Restrict access to the BuildKit control API to only trusted users and services. Implement robust authentication and authorization policies for all clients interacting with the BuildKit daemon to prevent unauthorized access and potential file system escapes. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests.

🔗 References (45)