Red Hat Security Advisory: Red Hat Quay 3.10.27
🔗 CVE IDs covered (12)
📋 Description
CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href CVE-2026-54770 — webob: WebOb: Open redirect vulnerability leading to phishing and token theft CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-77403 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via AMQP frame size negotiation CVE-2026-77404 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Connection configuration overwrite via unsanitized TLS path parameter injection CVE-2026-77406 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via signed-to-unsigned integer casting CVE-2026-77409 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service due to synchronous event channel blocking CVE-2026-77410 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via unbounded body buffer allocation CVE-2026-77412 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via Malicious AMQP Field Length CVE-2026-79921 — github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via oversized AMQP payloads CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-87776 — compression: compression: Denial of Service via memory leak on premature response close
🎯 Affected products23
- Red Hat Quay 3.10
- registry.redhat.io/quay/clair-rhel8@sha256:8e04a400ec1d0858bf9ab245c6642ed4a1534732680e8cb4e4794ef00d9d042b_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/clair-rhel8@sha256:ab68b002dc3a2922cbc7560c6a9cf4bc55d3f77b2ba3342c52265ca2276dcabb_ppc64le as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/clair-rhel8@sha256:d4ffc88ab95afd45622b6c34aa8cba121f23f280142aa87a20b69fe55ad2218a_s390x as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:70be7fae6fcf36f60baa6f4e7665e7a623be0029acfb59cc6eca7ce710a4cbfa_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:0550a3e9cd02023e257ad5f968f20f8935cf5306b67e47fc3ada8de01868cb30_s390x as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:31bad010fcdf9c90288f031b636365e88284f1f92d9d7d0c8ba4d48acf53ee29_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:778feefc8f14f00080370ac82d141e5527b516fb61c10194867fca64e88060be_ppc64le as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:307ff139c6f9aa5cc3321bfb9948b8a8e9ceb0b03c7d49689be2bfcf61555464_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-builder-rhel8@sha256:37e3228abafae37b531067ae0d039cc805192bf8e50d5e6c6244679c5cd800ed_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-builder-rhel8@sha256:6e6f2f67723f90493e49779c6da95d362336a90cbfa1669790e5f2d3cd2de1bd_ppc64le as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-builder-rhel8@sha256:ae811633f2bcc5e210fbbbcc1f744f08e91bb02936f21f447776811704bd8550_s390x as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:3ac12b6251e33a798bee205490dc71e07edd944e361f1c0179e9c6a9d97e4697_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:692d52b8581fcd5ab15e4680aeac07a89d269b383a80bb17bdbfabfbc4a35fda_ppc64le as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:a0ea3127139e341958e1ee0f447fac63b0ee126a58b2a9e2c98cc7e3c5677538_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:bafce57147154aaecbb272f7bae4261dc2630849de8f7040bde1696ee98165a3_s390x as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-operator-bundle@sha256:7a9584ff40c099b3960a27de4b3d389bb4f5027ecea2227cb4b4d99bcc9f1395_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-operator-rhel8@sha256:1238b19ec25cf908ecceb0c28cb6799268ec06df2be328bfaa98f2c4c0a38748_ppc64le as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-operator-rhel8@sha256:6efc8750cebbba36b1697de5b7c8328c66ad5972be2b889c5db5e8db68d4042d_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-operator-rhel8@sha256:dafe532443d267c54af2d516d91dcb8ddc7587496f328ad0b50c1751dbe17edb_s390x as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-rhel8@sha256:4795fd6aeefebcc69f1e3bdea5de2a0de743e9823bab09c540fac60ce97457ed_amd64 as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-rhel8@sha256:92cb4fa377bf8526ff5e5b6162fcceddaf9a0cc134c72b00886d7a01810a8039_s390x as a component of Red Hat Quay 3.10
- registry.redhat.io/quay/quay-rhel8@sha256:e64be4e2d395ed76a2995da770549a369049d3b5ab2809e0a8321242cd394666_ppc64le as a component of Red Hat Quay 3.10
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Applications utilizing the WebOb library should implement strict validation of redirect target URLs. Configure applications to only allow redirects to trusted, fully-qualified URIs or to strictly allowlist permitted redirect destinations. Reject any redirect target that does not begin with an expected trusted host or a validated relative path, ensuring no leading whitespace or control characters are present. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: To mitigate this issue, ensure that applications using the RabbitMQ amqp091-go client only connect to trusted AMQP brokers. Restrict network access for clients to only communicate with known, secure broker instances. This reduces the risk of a malicious or compromised broker exploiting the client's vulnerability during frame size negotiation. Workaround: Avoid accepting untrusted values for TLS certificate, key, CA, or server-name paths. Restrict write access to directories and environment settings used to configure those paths, and upgrade applications using amqp091-go to version 1.13.0 or later when available. Workaround: Do not allow untrusted users to control AMQP QoS prefetch settings. Validate configured values are non-negative, and update applications using amqp091-go when a fixed version is available. Workaround: Use adequately buffered notification channels and ensure event consumers continuously drain them. Update applications using amqp091-go when a fixed version is available. Workaround: Connect only to trusted AMQP brokers, protect broker credentials and transport security, and update applications using amqp091-go when a fixed version is available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests. Workaround: Update the compression middleware to version 1.8.2 or later. No supported workaround is currently available if the affected version cannot be updated.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:79366
- externalhttps://access.redhat.com/security/cve/CVE-2026-49825
- externalhttps://access.redhat.com/security/cve/CVE-2026-54770
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-77403
- externalhttps://access.redhat.com/security/cve/CVE-2026-77404
- externalhttps://access.redhat.com/security/cve/CVE-2026-77406
- externalhttps://access.redhat.com/security/cve/CVE-2026-77409
- externalhttps://access.redhat.com/security/cve/CVE-2026-77410
- externalhttps://access.redhat.com/security/cve/CVE-2026-77412
- externalhttps://access.redhat.com/security/cve/CVE-2026-79921
- externalhttps://access.redhat.com/security/cve/CVE-2026-82417
- externalhttps://access.redhat.com/security/cve/CVE-2026-87776
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_79366.json