CVE-2026-2376

medium
Published 2026-03-12 · Modified 2026-06-02
CVSS v3
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v4 NEW
—
not yet in upstream
VIR risk
5.4

Description

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.

Predictions

Exploit likelihood
64%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description mirror-registry: quay: quay: Server-side Request Forgery via open redirect vulnerability in web interface CVSS v3: 4.9 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N) Package state ProductPackageState mirror registry for Red Hat OpenShiftopenshift/mirror-registry-rhel8Fix deferred mirror registry for Red Hat OpenShift 2openshift/mirror-registry-rhel8Fix deferred Red Hat Quay…

Description

mirror-registry: quay: quay: Server-side Request Forgery via open redirect vulnerability in web interface

CVSS v3: 4.9 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N)

Package state

ProductPackageState
mirror registry for Red Hat OpenShiftopenshift/mirror-registry-rhel8Fix deferred
mirror registry for Red Hat OpenShift 2openshift/mirror-registry-rhel8Fix deferred
Red Hat Quay 3quay/quay-rhel8Fix deferred
Red Hat Quay 3quay/quay-rhel9Fix deferred

OS impact

OSVersionStatusFixed in
redhat rhel8.0not-affected
redhat rhel9.0not-affected

Application impact

VendorProductVersionsFixed
redhat redhatquay3.0.0
redhat redhatmirror_registry-

References

CWEs

CWE-601

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.