Medium severity5.5NVD Advisory· Published Jul 24, 2026· Updated Jul 24, 2026
CVE-2026-16910
CVE-2026-16910
Description
A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.