Red Hat Security Advisory: Red Hat Quay 3.17.5
🔗 CVE IDs covered (29)
📋 Description
CVE-2026-15792 — github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request CVE-2026-16221 — fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency CVE-2026-18255 — quay: quay: Global read-only superuser can view robot account tokens CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39822 — golang: Go os.Root: Symlink following vulnerability allows directory traversal CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-49477 — soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href CVE-2026-54770 — webob: WebOb: Open redirect vulnerability leading to phishing and token theft CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies
🎯 Affected products32
- Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:743cae8dd741cbdd285581abc24d2d1b54582ca20cd99e2548880be7ffed0c14_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:7ce10d84353efd35ac1905a3e8ec97df98e52eebe8ebe2c57f6434e4475df921_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:a3f9ceddc0476549ebd6486c12c78ba4ecb984664113027e1a97b15168660db8_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/clair-rhel9@sha256:e2077843bac48c84f6b5be2f102a84182a2fe33529dd84b7a2083641be6f9a29_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:be945c4a514ad0505f5443bfc4fea2b5ad8c37eaf862bc27a23a59221055fe4e_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:0a17557f786a723523b020cbcb6f028b06017a541cbce019606afb522fd89b6b_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:27414b7981b7082b4c8fac4ee33d2198c408daf171348bf6e1eb417304043484_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:868dc490afcd698634d6eed8a3e3d24bd51c72799036983c7cbd8418b7e881f5_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:aa472ac9529c09616fb003e9e1e19b439d5419175da48fed312466f45cab7cb2_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:31e87a0c686d00891488c9b3d8c42865d14de41d30002ef34656332ea23ddbfe_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:3cdd404b67d28045726d5a2a111783e2035e41ad7578291400314fa28035046f_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:bfcc4a075ee123df67852dc0418554fd4b7d1c5c2e267e677a5acb9b1f9c1a02_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:d5959b8d429159d79083766066cfcf73c052c55165ffd0f1dd9a603a2025bbbe_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:4fab76c5abe62723f30212f352d1ad5a16039eeb807d2a25d5ba2bf6fa25f702_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:6184ea13798a9263a9201d52eeae9d33e9e45f067d67fecd61d7da920283600f_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:795eac54582c1895ee2c8de04fa444874517b37236080b2c47820b38a1af98de_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-builder-rhel9@sha256:80db7ab49837c60087228b3d4b5fa25d4d226f5ab9bf60d3e36b25baf24b31c8_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:869fcd1ccebd6c4f3a1eec8c939b82261610d903c6335541e0769ff30b571c35_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:3f032f0b0cde9e1434480c10ad4744ef6675a22167c2b0e7146235f6d990404f_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:50d052bb40fe62b16baee5506a943d24ce0db4868d79e0818d882cc5c94a3fd3_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:900b9f7e9f4ce839b8c60d787077aac160391fcda242e750d0b96f1ebbece3db_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:bd7328761976e42372fa6245fd773e1c7445444cf602919b1ece98fe5c38f15b_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-bundle@sha256:1983e925bcc375294418f29089b1e2797bc1772d712fd4de005f3c31a5746440_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:7bdfca35d58d9a3c038320a83a4b19f2217cb08513e47a6cd5a06399c21c4fda_amd64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:819d159ab3eb7fc4d9261a1c8bad914c5c9bf7d469546ffd44e083286f480cee_ppc64le as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:9efb708dedf199d3537ddcf837d873a91ad565bc5500ac58fa346a2e0f67c995_arm64 as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-operator-rhel9@sha256:a8d42b5d8d4f7a9bfb836b68764b95e0ae1df8e2fd544a8c7d63862f9b20380d_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-rhel9@sha256:08a617f24b4b2b7e93b12d767b7d5eefe26e59147c90c60afb4262adfa2fe6c9_s390x as a component of Red Hat Quay 3.17
- registry.redhat.io/quay/quay-rhel9@sha256:7ebc95c858f32ceda0bc0bc3517374fab58b8c37c824f9fcd361b88c6077094d_amd64 as a component of Red Hat Quay 3.17
- +2 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Avoid building container images using BuildKit frontends from untrusted sources. A BuildKit frontend is typically specified using a "# syntax" directive at the top of a Dockerfile, or with the "--frontend" option to the "buildctl build" command. Only use frontend images that come from a trusted source. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Remove users who can not be trusted with robot account credentials from GLOBAL_READONLY_SUPER_USERS. Workaround: There is no mitigation for this issue other than updating the Go toolchain to Go 1.25.12 or Go 1.26.5. Programs compiled with Go >= 1.24 that do not use the os.Root API are not affected by this vulnerability. The os.Root API was introduced in Go 1.24. Go versions prior to 1.24 are not affected. This issue is fixed in Go 1.25.12 and Go 1.26.5. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: Applications utilizing the WebOb library should implement strict validation of redirect target URLs. Configure applications to only allow redirects to trusted, fully-qualified URIs or to strictly allowlist permitted redirect destinations. Reject any redirect target that does not begin with an expected trusted host or a validated relative path, ensuring no leading whitespace or control characters are present. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.
🔗 References (32)
- selfhttps://access.redhat.com/errata/RHSA-2026:74511
- externalhttps://access.redhat.com/security/cve/CVE-2026-15792
- externalhttps://access.redhat.com/security/cve/CVE-2026-16221
- externalhttps://access.redhat.com/security/cve/CVE-2026-18255
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39822
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-44705
- externalhttps://access.redhat.com/security/cve/CVE-2026-49477
- externalhttps://access.redhat.com/security/cve/CVE-2026-49825
- externalhttps://access.redhat.com/security/cve/CVE-2026-54770
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-67313
- externalhttps://access.redhat.com/security/cve/CVE-2026-67314
- externalhttps://access.redhat.com/security/cve/CVE-2026-67320
- externalhttps://access.redhat.com/security/cve/CVE-2026-67321
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74511.json