Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15927

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 6.8

Описание

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.

Отчет

This Important flaw in Red Hat Quay's repository-level mirror configuration allows an authenticated repository administrator to conduct Server-Side Request Forgery (SSRF). By providing a specially crafted hostname, an attacker can force the Quay mirror worker to connect to internal network services or cloud metadata endpoints, potentially exposing sensitive internal resources. This risk is limited to actions performed by an authenticated administrator.

Меры по смягчению последствий

Restrict network egress from Quay mirror worker pods/containers using network policies or firewall rules to block access to internal network ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and cloud metadata endpoints (169.254.169.254, metadata.google.internal). Limit repository creation and admin privileges to trusted users via Quay's RBAC configuration. If repository-level mirroring is not required, disable the feature or restrict access to the mirror API endpoints through a reverse proxy.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
mirror registry for Red Hat OpenShift 2openshift/mirror-registry-rhel8Will not fix
Red Hat Quay 3.1quay/quay-rhel8FixedRHSA-2026:5352011.08.2026
Red Hat Quay 3.12quay/quay-rhel8FixedRHSA-2026:5296810.08.2026
Red Hat Quay 3.17quay/quay-rhel9FixedRHSA-2026:5439512.08.2026
Red Hat Quay 3.9quay/quay-rhel8FixedRHSA-2026:5093105.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2501256quay: mirror-registry: SSRF: repo-level mirror accepts external_reference without URL validation

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
28 дней назад

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.

CVSS3: 6.8
github
28 дней назад

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.

6.8 Medium

CVSS3