Description
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
Affected products
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:19375
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:21017
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:22465
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:22629
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:22840
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:23361
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:24853
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:28441
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-32589
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2446963
Updated 20m ago · 8 sources