VendorsRed Hatquayall versions
Vulnerabilities

Red Hat Quay

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

39CVEs
CVE-2021-3762
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.
Published 2022-03-03 · Modified
9.8EPSS 0.048
CVE-2020-27832
A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into performing a malicious action to impersonate the target user. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-05-27 · Modified
9.0EPSS 0.009
CVE-2022-1227
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
Published 2022-04-29 · Modified
8.8EPSS 0.042
CVE-2019-3864
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.
Published 2020-01-21 · Modified
8.8EPSS 0.004
CVE-2026-32590
Mirror-registry: remote code execution using pickle deserialization
Published 2026-04-08 · Modified
8.8EPSS 0.004
CVE-2026-74243
Quay: unauthenticated secscan notification endpoint in quay when psk is unset
Published 2026-08-14 · Analyzed
8.2EPSS 0.003
CVE-2026-6848
Quay: red hat quay: authentication bypass allows privileged actions without valid credentials
Published 2026-04-22 · Analyzed
8.1EPSS 0.003
CVE-2019-9515
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.874
CVE-2019-9514
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.828
CVE-2019-9513
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.816
CVE-2019-9511
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.595
CVE-2019-9517
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.279
CVE-2019-9518
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.254
CVE-2026-44495
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Published 2026-06-11 · Modified
7.7EPSS 0.009
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2019-9516
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.5EPSS 0.563
CVE-2020-10735
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
Published 2022-09-09 · Modified
7.5EPSS 0.072
CVE-2026-74245
Quay: unauthenticated exported logs download in quay
Published 2026-08-14 · Analyzed
7.5EPSS 0.003
CVE-2026-74244
Quay: stripe webhook accepts forged events without signature verification in quay
Published 2026-08-14 · Analyzed
7.5EPSS 0.001
CVE-2026-32589
Mirror-registry: quay: insecure direct object reference in blobupload
Published 2026-04-08 · Modified
7.4EPSS 0.002
CVE-2026-74247
Quay: ssrf via build archive_url in quay build api
Published 2026-08-14 · Analyzed
7.1EPSS 0.001
CVE-2022-2447
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
Published 2022-09-01 · Modified
6.6EPSS 0.007
CVE-2023-4956
Quay: clickjacking on config-editor page severity
Published 2023-11-07 · Modified
6.5EPSS 0.005
CVE-2026-2377
Mirror-registry: quay: quay: server-side request forgery via log export functionality
Published 2026-04-08 · Modified
6.5EPSS 0.004
CVE-2025-4374
Quay: incorrect privilege assignment
Published 2025-05-06 · Modified
6.5EPSS 0.003
CVE-2023-4959
Quay: cross-site request forgery (csrf) on config-editor page
Published 2023-09-15 · Modified
6.5EPSS 0.003
CVE-2026-74241
Quay: ldap referral filter injection in quay external ldap authentication
Published 2026-08-14 · Analyzed
6.5EPSS 0.002
CVE-2019-10205
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored in the registry.
Published 2020-01-02 · Modified
6.3EPSS 0.003
CVE-2019-3865
A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name.
Published 2020-06-22 · Modified
6.1EPSS 0.007
CVE-2026-32591
Mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
Published 2026-04-08 · Modified
5.5EPSS 0.003
CVE-2023-3384
Quay: stored cross site scripting
Published 2023-07-24 · Modified
5.4EPSS 0.005
CVE-2026-74240
Quay: jwt claim validation bypasses in quay federated robot and sso authentication
Published 2026-08-14 · Analyzed
5.4EPSS 0.002
CVE-2026-2376
Mirror-registry: quay: quay: server-side request forgery via open redirect vulnerability in web interface
Published 2026-03-12 · Analyzed
5.4EPSS 0.002
CVE-2024-9683
Quay: quay allows successful authentication with trucated version of the password
Published 2024-10-17 · Analyzed
5.3EPSS 0.003
CVE-2026-74242
Quay: repository notification uuid idor in quay api
Published 2026-08-14 · Analyzed
5.3EPSS 0.003
CVE-2019-3867
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Red Hat Quay 2 and 3 are vulnerable to this issue.
Published 2021-03-18 · Modified
4.4EPSS 0.003
CVE-2020-14313
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
Published 2020-08-11 · Modified
4.3EPSS 0.009
CVE-2020-27831
A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
Published 2021-05-26 · Modified
4.3EPSS 0.005
CVE-2024-5891
Quay: unauthorized user may authenticate via oauth application token
Published 2024-06-12 · Modified
4.2EPSS 0.002