Red Hat Quay
6 known vulnerabilities in Red Hat Quay, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-102576 CVSS 4.2 medium A flaw was found in Quay. A remote attacker could trick a user into logging in through a crafted link, resulting in cross-site scripting…
- CVE-2026-102295 CVSS 5.4 medium A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute…
- CVE-2026-85469 CVSS 8.0 high A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action`…
- CVE-2026-79705 CVSS 4.5 medium A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing…
- CVE-2026-79699 CVSS 4.4 medium A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can…
- CVE-2026-33894 CVSS 7.5 high Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA…