RHSA-2026:77656HighCVSS 8.8

Red Hat Security Advisory: Red Hat Quay 3.9.27

Published
October 7, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (15)

📋 Description

CVE-2026-17106 — github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href CVE-2026-54770 — webob: WebOb: Open redirect vulnerability leading to phishing and token theft CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-77403 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via AMQP frame size negotiation CVE-2026-77404 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Connection configuration overwrite via unsanitized TLS path parameter injection CVE-2026-77406 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via signed-to-unsigned integer casting CVE-2026-77409 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service due to synchronous event channel blocking CVE-2026-77410 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via unbounded body buffer allocation CVE-2026-77412 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via Malicious AMQP Field Length CVE-2026-79921 — github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via oversized AMQP payloads CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-87776 — compression: compression: Denial of Service via memory leak on premature response close

🎯 Affected products23

  • Red Hat Quay 3.9
  • registry.redhat.io/quay/clair-rhel8@sha256:929267241996772aa38f66050d8a3da2fb2486ecbc9947713b0985360ed5c08b_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/clair-rhel8@sha256:bc89c3dd056f1158c159d9abcf38ede260cf975941877b73e97cde6735534b83_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/clair-rhel8@sha256:fedfa95c3de2182f416a7ece5371844698891b521e5667be0b77b766a2216bb3_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:5ed9fd3f7e0cb37d5af57d47034f09f86faff23ce312e5ef855810b93ea95611_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:01c8b93ac89087440a9c53e0f727476e529abf515d0a7d531ff1216fee9753fd_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:03ea617a30b7daab5cc0d7eb994f8b3c83be7af5cecbbca7bd5493be712fb13f_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:a95fe1043f64c9da4c6b7be35848a91a013a89d718f6dd38d2ea6fb257790195_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:cb5021166e79bc7a3410ca5a8b50d8327a681d9ec66cfb2b44aa36c9a8b22e5b_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:04d793532101024985034fcfa26aeca2bbe9cdc4b8d4c0dcfdb5deffe6eca839_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:373b765b533fc4740ed401fc40b69d487213168633d711556a0bea59b02a527e_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:8b3e0a8e7ae705f531ccf98b0d2cdb38b205e3ef11b5e3b9c420f6868a58ad90_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:b587c26256a429d4660375a8ea87674656cb3619b2dae592f0ea94ea6ee43a30_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:069e37db34381a35d170461a66b904ca7fb8ffa3f0e71b4ded079d5bedb458d5_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:3d287bd34a69166eeb859c7245a91c6e95b2f729a51cc74060d7ae18052053f4_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:e46445ea2b541e99e53cbf1af373f993f23ac94550c4778903b427015d9a19d7_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-operator-bundle@sha256:d8ce8cee8338f7e7dc0c86405606cf610402768e504d7dfb1ea4a0e6795320ac_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:044a80a50382e6b9833811b6e5fa9a81427780332aaab3096302681abeecd8f1_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:1cc683582ba1700545d5648f17735d680fd7a8c17fca6021fb52b9d2192e1fa2_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:5d2c73aff1bbcc5180996c6697f878072716d7425133edb3846384a22ca9155c_s390x as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-rhel8@sha256:bf7ee07a25cd269986e054e0b04daebcb250b04fc3de60055a17142a932f5530_ppc64le as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-rhel8@sha256:f33464ccc07e05781c2ec093df7fd9093b5ab0aae6435c11d632cc1332a560ee_amd64 as a component of Red Hat Quay 3.9
  • registry.redhat.io/quay/quay-rhel8@sha256:fb430174cec4428f0824787842e18f04d5eea0f5355cc90d1919ee1007086202_s390x as a component of Red Hat Quay 3.9

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, avoid processing tar archives from untrusted sources. When handling archives from potentially untrusted origins, ensure that the extraction process is executed with the least privileges necessary to limit the impact of any arbitrary file write attempts. Workaround: Applications utilizing the WebOb library should implement strict validation of redirect target URLs. Configure applications to only allow redirects to trusted, fully-qualified URIs or to strictly allowlist permitted redirect destinations. Reject any redirect target that does not begin with an expected trusted host or a validated relative path, ensuring no leading whitespace or control characters are present. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: To mitigate this issue, ensure that applications using the RabbitMQ amqp091-go client only connect to trusted AMQP brokers. Restrict network access for clients to only communicate with known, secure broker instances. This reduces the risk of a malicious or compromised broker exploiting the client's vulnerability during frame size negotiation. Workaround: Avoid accepting untrusted values for TLS certificate, key, CA, or server-name paths. Restrict write access to directories and environment settings used to configure those paths, and upgrade applications using amqp091-go to version 1.13.0 or later when available. Workaround: Do not allow untrusted users to control AMQP QoS prefetch settings. Validate configured values are non-negative, and update applications using amqp091-go when a fixed version is available. Workaround: Use adequately buffered notification channels and ensure event consumers continuously drain them. Update applications using amqp091-go when a fixed version is available. Workaround: Connect only to trusted AMQP brokers, protect broker credentials and transport security, and update applications using amqp091-go when a fixed version is available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests. Workaround: Update the compression middleware to version 1.8.2 or later. No supported workaround is currently available if the affected version cannot be updated.

🔗 References (18)