Junglewise Threat Intelligence

CVE-2026-32591: Red Hat Quay SSRF in Proxy Cache configuration

CVE-2026-32591 · Severity: medium · CVSS 5.2 · Published 2026-04-08

Technologies: Red Hat Quay config-tool. Vendors: Red Hat.

Executive brief

Red Hat Quay is a platform used to store and manage container images. A security vulnerability in its Proxy Cache feature allows an administrator of a specific organization to force the server to connect to internal network resources that should be private. This could lead to the exposure of sensitive internal data or cloud infrastructure metadata that is not intended to be accessible from the application.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, the application fails to validate the provided hostname against internal address ranges or private IP space. An authenticated attacker with organization administrator privileges can provide a crafted hostname to force the Quay server to make requests to internal network services or cloud metadata endpoints. This can result in unauthorized access to internal resources or sensitive information disclosure. The issue is addressed in Red Hat Quay version 3.16.4.

Affected products

  • Red Hat Quay 3.0.0 through 3.16.3
  • Red Hat Mirror Registry for Red Hat OpenShift 2.0

Timeline

  • 2026-03-12: other: Initial internal report/import
  • 2026-04-08: disclosed: NVD Published Date
  • 2026-05-19: patched: Red Hat Quay 3.16.4 released

References