VYPR

quay

by Quay

CVEs (2)

  • CVE-2026-11569MedJun 8, 2026
    risk 0.35cvss 5.4epss

    A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through the CDN, enabling stored…

  • CVE-2026-2376MedMar 12, 2026
    risk 0.32cvss 4.9epss 0.00

    A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without…