RHSA-2026:7314HighCVSS 9.1

Red Hat Security Advisory: Red Hat Quay 3.14.7

Published
April 9, 2026
Last Modified
July 29, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-27962 — authlib: Authlib: Authentication bypass due to JWK Header Injection vulnerability

🎯 Affected products32

  • Red Hat Quay 3.14
  • registry.redhat.io/quay/clair-rhel8@sha256:2f4708fcb6d33a83959cf9d5733e12910b8f64a5fcf29051fd67803c8b103496_arm64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/clair-rhel8@sha256:547aee162884d7561359375f6eada553365072bff6f51b212a228e066172ed1f_ppc64le as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/clair-rhel8@sha256:702d3486624a33c0b929547f59a7491f2b9246be5e4d39426ca48a3d2275e6f1_s390x as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/clair-rhel8@sha256:b1b56d8dd5b46faae23d6024411c4f9992a370d10965699608e3358c2f6c66b6_amd64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:2915b3d961ac8a528af082803772c04edb5171a4590386935a1912f2718ed060_amd64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:20938513fd9709176b158553286b615f857e2458cd3515c4f31f585f944a265f_arm64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:3818efd3c5bfc2e39819f11323c8075b09a72b4daff70946f8ee231a1dceb6e3_ppc64le as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:6c69e9ffcf29e4769d14d1de2f24ae52231237803804f77907742d7591397201_amd64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:6e721e2b88de017546485b427aeda9115e8596d875f71de7c7c0f95239136402_s390x as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:92aeb229c424e0335d5f921844b049123153fa07f76c4e03c8cdd9b5476dac61_ppc64le as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:b3edfd46a42bd6769ee81d620a958b84d4f2bfc3459370abbb6e82ef4fcfc6a2_s390x as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:c35821e22efa8a22625a725bf8130dc183d235e4f9bb851df082523f90658898_amd64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:e5750707f2e4b31acb300dda672c7763b3643391254369c7c1835675dc9637c6_arm64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:689af696935a204022de3c25fc5a4095883b90e0604715f500f3bef50f05ed5f_s390x as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:6ff08f45f119498ac294e216ae39f2385e8b5f1e0e348a3cc7046db87c4947a5_arm64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:83d96120338afda38bf9eb59fd514124adeb772619e1457eb07ee242b1e56cc1_ppc64le as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:a58b0fd427edece6e7fcfd2246a9f00d14751b7b21f09dcc28cd2f44cdab009b_amd64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:250d48c5e6066940bcfc19d9294c85c05a0137212aec369ec43aba9f8d65f74f_amd64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:2ad22e69cbc9e4520336d2c810184943aebb98dbb7dcb839a09c715affe41687_amd64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:4f3813bbe0dc9e205dd80a10cf6624dbf85647ab4824f17b7ea7aa8d815923bb_s390x as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:b56a52a12c4a430ae3b4d5b4ca0ccd4174f3aab52b1dc507e3e951602b5fcfde_arm64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:dbf5e9b12d36813a77908b6d769a82e46771c87492a42844d4a5bf1562308874_ppc64le as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-operator-bundle@sha256:fad9d7440c99df5b1227d6581415c4150f3cbcfe2fbae308bd70bdbcb06bdbeb_amd64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:33591ec5fcf2e9a1f749e6f37ff6df06a2779f6cc7fb3b19013c47ab782b41f8_s390x as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:3aee5e0bd4ae76ffab05c911b71a30e5a5f59eeafd958f4eedf8f48d5c8e2d59_ppc64le as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:923655c52a9e78f2185973e42c732c1dec05760e6b790631de658886f14412c9_amd64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:b5fb433f5bd294782da89cdda2aebf4cd378a6d1cf89d0ffd50b139f39894d54_arm64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-rhel8@sha256:01f890a5280ddd4093134dc21578f8a5f06cdade4b9a6d59f31ca8deec8c43c3_arm64 as a component of Red Hat Quay 3.14
  • registry.redhat.io/quay/quay-rhel8@sha256:3f44613559972c360a7e0cfce386ee3d840bc36dcb16175780835d53babe482f_amd64 as a component of Red Hat Quay 3.14
  • +2 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11458 Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters.

🔗 References (5)