Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.5) | — | — | Redhat QuayAI | 5/10/2026 | 5/10/2026 | A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to… | |
| Recibida | Media (4.2) | — | — | Redhat QuayAI | 5/10/2026 | 5/10/2026 | A flaw was found in Quay. A remote attacker could trick a user into logging in through a crafted link, resulting in cross-site scripting (XSS). Because the application does not validate the redirect destination before navigating, this flaw allows the execution of arbitrary script in the context of the victim's… | |
| Recibida | Media (5.4) | — | — | Redhat QuayAI | 5/10/2026 | 5/10/2026 | A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaScript code within a user's browser session. By tricking a logged-in user into visiting a specially crafted link, an attacker can exploit improper input sanitization to… | |
| Pendiente de análisis | Alta (8) | 0.52% | — | Noelware Docker-manifest-actionAIQuay Builder-qemuAI | 16/9/2026 | 18/9/2026 | A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials… | |
| Analizada | Alta (7.1) | 0.24% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an… | |
| Analizada | Alta (7.5) | 0.42% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure,… | |
| Analizada | Alta (7.5) | 0.23% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized… | |
| Analizada | Alta (8.2) | 0.46% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths.… | |
| Analizada | Media (4.4) | 0.33% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to… | |
| Analizada | Media (6.5) | 0.31% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle… | |
| Analizada | Media (5.4) | 0.29% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from… | |
| Pendiente de análisis | Alta (7.2) | 0.75% | — | Redhat QuayAI | 29/7/2026 | 1/10/2026 | A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account. | |
| Pendiente de análisis | Media (5.5) | 0.29% | — | Redhat QuayAI | 24/7/2026 | 24/7/2026 | A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that… | |
| Pendiente de análisis | Media (6.8) | 0.60% | — | SkopeoAIRedhat QuayAI | 21/7/2026 | 22/9/2026 | A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator… | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… | |
| Pendiente de análisis | Media (5.4) | 0.14% | — | Redhat QuayAI | 8/6/2026 | 23/7/2026 | A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through the CDN, enabling stored cross-site scripting when a victim visits the… | |
| Rechazada | Sin puntuar | — | — | Quay ClaircoreAIRedhat ClairAI | 1/6/2026 | 27/7/2026 | Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is… | |
| Pendiente de análisis | Baja (2.7) | 0.20% | — | Quay Config ToolAI | 29/5/2026 | 21/7/2026 | A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL query parameters during POST requests to the GitLab endpoint. This insecure transmission can lead to the disclosure of… | |
| Pendiente de análisis | Media (4.1) | 0.19% | — | Project Quay Config ToolAI | 29/5/2026 | 21/7/2026 | A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the… | |
| Analizada | Alta (8.1) | 0.38% | — | Redhat Quay | 22/4/2026 | 17/6/2026 | A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot account creation, the re-authentication prompt can be bypassed. This allows a user with a timed-out session, or an attacker with access to an idle authenticated browser… | |
| Modificada | Alta (8.8) | 0.79% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 9/9/2026 | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server. | |
| Modificada | Media (6.3) | 0.43% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 10/9/2026 | A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel… | |
| Modificada | Media (6.5) | 0.40% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 10/9/2026 | A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery… | |
| Modificada | Media (5.5) | 0.46% | — | Redhat Mirror Registry FOR RED HAT OpenshiftRedhat Quay | 8/4/2026 | 22/9/2026 | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization… | |
| Analizada | Media (5.4) | 0.16% | — | Redhat QuayRedhat Mirror Registry | 12/3/2026 | 17/6/2026 | A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing… |