High severity7.1NVD Advisory· Published Apr 8, 2026· Updated Jun 9, 2026
CVE-2026-32590
CVE-2026-32590
Description
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- access.redhat.com/security/cve/CVE-2026-32590nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- access.redhat.com/errata/RHSA-2026:19375nvd
- access.redhat.com/errata/RHSA-2026:21017nvd
- access.redhat.com/errata/RHSA-2026:22465nvd
- access.redhat.com/errata/RHSA-2026:22629nvd
- access.redhat.com/errata/RHSA-2026:22840nvd
- access.redhat.com/errata/RHSA-2026:23361nvd
- access.redhat.com/errata/RHSA-2026:24833nvd
- access.redhat.com/errata/RHSA-2026:24853nvd
News mentions
0No linked articles in our index yet.