RHSA-2026:79546HighCVSS 8.8

Red Hat Security Advisory: Red Hat Quay 3.12.23

Published
October 8, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2026-17106 — github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction CVE-2026-49825 — lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href CVE-2026-54770 — webob: WebOb: Open redirect vulnerability leading to phishing and token theft CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-77403 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via AMQP frame size negotiation CVE-2026-77404 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Connection configuration overwrite via unsanitized TLS path parameter injection CVE-2026-77406 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via signed-to-unsigned integer casting CVE-2026-77409 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service due to synchronous event channel blocking CVE-2026-77410 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via unbounded body buffer allocation CVE-2026-77412 — github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via Malicious AMQP Field Length CVE-2026-79921 — github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via oversized AMQP payloads CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-87776 — compression: compression: Denial of Service via memory leak on premature response close CVE-2026-94603 — podman: podman: The podman run command can be instructed to disable almost all sandboxing - including user-requested sandboxing - by image annotation

🎯 Affected products29

  • Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:26fdc3a97583a3fd35ffa6159e20305c9178783a448adbce4535727b42cf6b73_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:96d80133cf840fdacb7cee6001fa520c59afe81bd71255072f6bb2877d559c85_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:c4b68e48a21054297e69183acd7e75af9cbf921c8c3393c035d7c232556da38e_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/clair-rhel8@sha256:c65cda67105cfc8f9ac2aea6474c1916d1d6f934e7fa47f31e1625c139409063_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:517e924e8e3244ff9b8f5b49fa278374fb12ea9d0ec14340ac7d4075dc32e13e_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:29787be24b421050acfac3a2984b0cdd604fe8317c08cf6a770c9da4feaec788_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:3616032118696b3e6c32dd2b7587c7883f3c3dcbe6c06048680c4b77624b840a_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:62e46ba17b350e4693d84799d6f1774f616b092fc7af54f9a12eda97d19c8d55_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-bridge-operator-rhel8@sha256:dc409ca4f62d7a1be328bf57ce600e95874404c28253f3e8f12ff9f7b73a089c_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:e17bc5c1861f15d8ce0f7456a0c717ae2fb94b8ba5b8ee134aa22c30487c5191_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:020fc4977610b270e4db808a537cf8a3e7c9a55945453fc22fe61b4783526349_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:046bc123b3b2b76fd9eb6b2694227a737c14b291cdf0bd45e15bdedbb5dbf91c_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:bea0df1cd41fd9c1a1b73e355521a5fb5b19bb1586e9a28a9e5b35b39a2cec58_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-builder-rhel8@sha256:e0b03ac73016760a8488ee0a5a4f44a9d23480ed16353efa720c8053c4bcc12a_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:42df3d497bb31280c53b2ea87f44a9473a07d09050789071dbfbbc5f148547a6_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:38e9d3c5fc7da82ad6ed222f0a5398221c473b19c859a61445b0e11b7a68e921_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:3efb593c1e3b66c8ed13e3d167855d6bb715ed0a56cb92c7654b435b068a3eaf_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:7febcf3c63f9b2d76e07a9a55abf5fc821ba89c35b29520ceb6bc54c392109da_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-container-security-operator-rhel8@sha256:8f424209de10bc294e48867ee809cb1c0d6540c2a7934791f4e9d4d0d694930a_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-bundle@sha256:5f010fc20c3ec4d45088e7d95434274798f0eb930f33ed56ff0cd4b8c93a7658_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:12360bc756ef0299c8123bc86c9b2144543e64dc8d0f56fa47052121aec08979_amd64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:a056ea6ce6932dfda026ba4307e4104f21bcf105cf6e0f1a3c580e3afa57091d_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:ebffcfc2b68067d6e030399244aeba69174edcd6217a0d0e7969b48df81dd3b7_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-operator-rhel8@sha256:ffab5c4cdcf115f53d5f5c76291fc1ba3beaa54462a47804fc2656df5b55f9ad_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:0d940ea3606dc30dfe84e7ff948001bbc8b8f9c4b157f2370523eb2cb32beb45_ppc64le as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:2f59d49e7181a61c3be8fd05af718a9d70ad3cc56778fd7d36f7d8a3cd8a8eab_arm64 as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:4c215f73501c07019a75a93f71625003d2f9965f012ff306703ae9f06e5a2090_s390x as a component of Red Hat Quay 3.12
  • registry.redhat.io/quay/quay-rhel8@sha256:e6a20eedbd78dd92041908c07446e3e9a1e29dade3e4d968c74f85c38c157078_amd64 as a component of Red Hat Quay 3.12

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, avoid processing tar archives from untrusted sources. When handling archives from potentially untrusted origins, ensure that the extraction process is executed with the least privileges necessary to limit the impact of any arbitrary file write attempts. Workaround: Applications utilizing the WebOb library should implement strict validation of redirect target URLs. Configure applications to only allow redirects to trusted, fully-qualified URIs or to strictly allowlist permitted redirect destinations. Reject any redirect target that does not begin with an expected trusted host or a validated relative path, ensuring no leading whitespace or control characters are present. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: To mitigate this issue, ensure that applications using the RabbitMQ amqp091-go client only connect to trusted AMQP brokers. Restrict network access for clients to only communicate with known, secure broker instances. This reduces the risk of a malicious or compromised broker exploiting the client's vulnerability during frame size negotiation. Workaround: Avoid accepting untrusted values for TLS certificate, key, CA, or server-name paths. Restrict write access to directories and environment settings used to configure those paths, and upgrade applications using amqp091-go to version 1.13.0 or later when available. Workaround: Do not allow untrusted users to control AMQP QoS prefetch settings. Validate configured values are non-negative, and update applications using amqp091-go when a fixed version is available. Workaround: Use adequately buffered notification channels and ensure event consumers continuously drain them. Update applications using amqp091-go when a fixed version is available. Workaround: Connect only to trusted AMQP brokers, protect broker credentials and transport security, and update applications using amqp091-go when a fixed version is available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests. Workaround: Update the compression middleware to version 1.8.2 or later. No supported workaround is currently available if the affected version cannot be updated.

🔗 References (17)