VendorsRed Hatquayany version
Vulnerabilities

Red Hat Quay any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-27832
A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into performing a malicious action to impersonate the target user. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-05-27 · Modified
9.0EPSS 0.009
CVE-2019-3864
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.
Published 2020-01-21 · Modified
8.8EPSS 0.004
CVE-2026-44495
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Published 2026-06-11 · Modified
7.7EPSS 0.010
CVE-2025-4374
Quay: incorrect privilege assignment
Published 2025-05-06 · Modified
6.5EPSS 0.003
CVE-2020-14313
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the existence of private repositories within any namespace.
Published 2020-08-11 · Modified
4.3EPSS 0.009
CVE-2020-27831
A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notifications.
Published 2021-05-26 · Modified
4.3EPSS 0.005