Medium severity6.5NVD Advisory· Published Apr 8, 2026· Updated Jun 9, 2026
CVE-2026-2377
CVE-2026-2377
Description
A flaw was found in mirror-registry. Authenticated users can exploit the log export feature by providing a specially crafted web address (URL). This allows the application's backend to make arbitrary requests to internal network resources, a vulnerability known as Server-Side Request Forgery (SSRF). This could lead to unauthorized access to sensitive information or other internal systems.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- access.redhat.com/security/cve/CVE-2026-2377nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- access.redhat.com/errata/RHSA-2026:19375nvd
- access.redhat.com/errata/RHSA-2026:21017nvd
- access.redhat.com/errata/RHSA-2026:22629nvd
- access.redhat.com/errata/RHSA-2026:22840nvd
- access.redhat.com/errata/RHSA-2026:23361nvd
- access.redhat.com/errata/RHSA-2026:24853nvd
News mentions
0No linked articles in our index yet.