Junglewise Threat Intelligence

CVE-2026-2377: Red Hat mirror-registry SSRF in log export feature

CVE-2026-2377 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: Red Hat Quay config-tool. Vendors: Red Hat.

Executive brief

A security vulnerability has been identified in Red Hat mirror-registry and Quay, tools used to manage and mirror container images. An authenticated user can exploit the log export feature to trick the application into making unauthorized requests to internal network resources. This could allow an attacker to access sensitive internal information or interact with other private systems that are not normally accessible from the outside.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the log export functionality of Red Hat mirror-registry and Quay. The flaw is rooted in the application's handling of the 'callback_url' parameter, which is processed asynchronously by a backend worker. An authenticated attacker can provide a specially crafted URL, causing the backend to perform arbitrary HTTP requests that follow redirects and preserve methods/bodies. This allows the attacker to bypass network segmentation and probe or interact with internal services. The issue is addressed in Quay version 3.16.4 and via Red Hat security advisory RHSA-2026:19375.

Affected products

  • Red Hat mirror-registry 2.0
  • Red Hat Quay 3.16.4
  • Red Hat Mirror Registry for Red Hat OpenShift

Timeline

  • 2026-02-11: other: Vulnerability reported to Red Hat Bugzilla
  • 2026-04-08: disclosed: Initial NVD publication
  • 2026-05-19: patched: Red Hat security advisory RHSA-2026:19375 issued

References

Related threats