CVE-2026-74244
EUVD-2026-5882114.08.2026, 23:16
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | openshift_update_service | - |
| redhat | quay | 3.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration