Executive brief
Red Hat Quay is a platform used to store and manage container images. A security flaw in the image upload process allows a user who has permission to upload to one area of the registry to interfere with uploads happening in other areas, even those they shouldn't be able to see. This could allow an attacker to view, change, or delete another user's container data while it is being uploaded, potentially leading to the deployment of compromised software.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the OCI blob upload protocol of Red Hat Quay and Mirror Registry for Red Hat OpenShift. The flaw is located in the BlobUpload functionality, specifically involving the 'sha_state' database column. An authenticated attacker with push access to at least one repository can exploit this by manipulating user-controlled keys to access in-progress blob uploads belonging to other tenants. This allows the attacker to read, modify, or cancel uploads in repositories where they lack permissions. The vulnerability is addressed in Red Hat Quay version 3.16.4.
Affected products
- Red Hat Quay 3.0.0, 3.16.4
- Red Hat Mirror Registry for Red Hat OpenShift 2.0
Timeline
- 2026-03-12: other: Initial internal report in Bugzilla
- 2026-04-08: disclosed: NVD publication date
- 2026-05-19: patched: RHSA-2026:19375 advisory issued for Quay 3.16.4