VYPR

Quay

by Red Hat

Source repositories

CVEs (46)

  • CVE-2024-3623MedApr 25, 2024
    risk 0.42cvss 6.5epss 0.00

    A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same…

  • CVE-2023-4956MedNov 7, 2023
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. During the pentest, it has been detected that the…

  • CVE-2023-4959MedSep 15, 2023
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The config-editor page is used to configure the Quay instance.…

  • CVE-2019-10205MedJan 2, 2020
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.

  • CVE-2019-3865MedJun 22, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name.

  • CVE-2026-44495HigJun 11, 2026
    risk 0.39cvss 7.0epss 0.01

    Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted…

  • CVE-2026-74245MedAug 14, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This…

  • CVE-2026-74244MedAug 14, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful…

  • CVE-2026-16910MedJul 24, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses…

  • CVE-2026-74240MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an…

  • CVE-2026-11569MedJun 8, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through the CDN, enabling stored…

  • CVE-2026-6848MedApr 22, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with…

  • CVE-2023-3384MedJul 24, 2023
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish…

  • CVE-2026-74242MedAug 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses.…

  • CVE-2026-74241MedAug 14, 2026
    risk 0.31cvss 4.8epss 0.00

    A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter…

  • CVE-2024-9683MedOct 17, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement.  While the risk is relatively low due to the…

  • CVE-2020-27831MedMay 27, 2021
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.

  • CVE-2020-14313MedAug 11, 2020
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.

  • CVE-2026-74247MedAug 14, 2026
    risk 0.27cvss 4.2epss 0.00

    A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests…

  • CVE-2026-10052MedMay 29, 2026
    risk 0.27cvss 4.1epss 0.00

    A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform…