Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16910

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application.

Отчет

This Moderate flaw in Red Hat Quay's notification webhook dispatch allows an authenticated repository administrator to conduct blind Server-Side Request Forgery (SSRF). The Quay worker issues requests to attacker-specified URLs when notifications fire, but response data is not returned to the attacker, limiting exploitable impact to network probing and unauthenticated side-effects on internal services.

Меры по смягчению последствий

Restrict network egress from Quay worker pods/containers using network policies or firewall rules to block outbound connections to internal network ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and cloud metadata endpoints (169.254.169.254). Limit repository creation and admin privileges to trusted users. Configure WEBHOOK_HOSTNAME_BLACKLIST in Quay config to include known internal hostnames and IP ranges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Update Serviceopenshift-update-service/openshift-update-service-rhel8Fix deferred
Red Hat Quay 3quay/quay-rhel8Under investigation
Red Hat Quay 3quay/quay-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2506685quay: SSRF in Red Hat Quay notification webhooks (Slack/generic)

EPSS

Процентиль: 12%
0.00213
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
25 дней назад

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application.

CVSS3: 5.5
github
24 дня назад

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application.

EPSS

Процентиль: 12%
0.00213
Низкий

5.5 Medium

CVSS3