CVE-2026-74247
EUVD-2026-5882314.08.2026, 23:16
A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | openshift_update_service | - |
| redhat | quay | 3.0.0 |
𝑥
= Vulnerable software versions