Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32590

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

Отчет

Exploitation requires valid login credentials. The attacker must be authenticated to the registry, either through the web interface or through a container tool such as Podman.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
mirror registry for Red Hat OpenShiftopenshift/mirror-registry-rhel8Will not fix
mirror registry for Red Hat OpenShift 2.0openshift/mirror-registry-rhel8FixedRHSA-2026:2844123.06.2026
Red Hat Quay 3.1quay/quay-rhel8FixedRHSA-2026:2284003.06.2026
Red Hat Quay 3.12quay/quay-rhel8FixedRHSA-2026:2262902.06.2026
Red Hat Quay 3.14quay/quay-rhel8FixedRHSA-2026:2101726.05.2026
Red Hat Quay 3.15quay/quay-rhel8FixedRHSA-2026:2485309.06.2026
Red Hat Quay 3.16quay/quay-rhel9FixedRHSA-2026:1937519.05.2026
Red Hat Quay 3.17quay/quay-rhel9FixedRHSA-2026:2246502.06.2026
Red Hat Quay 3.17quay/quay-rhel9FixedRHSA-2026:2483309.06.2026
Red Hat Quay 3.18quay/quay-rhel9FixedRHSA-2026:4808529.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2446964mirror-registry: remote code execution using pickle deserialization

EPSS

Процентиль: 34%
0.00413
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
4 месяца назад

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

CVSS3: 7.1
github
4 месяца назад

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

EPSS

Процентиль: 34%
0.00413
Низкий

7.1 High

CVSS3