Executive brief
Red Hat Quay is a container image registry platform used by enterprises to store and manage container images. An attacker can exploit a flaw in its billing webhook handler to forge fake billing events without proper verification, potentially resetting namespace build quotas to maximum and sending unsolicited billing emails to administrators, disrupting resource management and user operations.
Technical details
The vulnerability is an improper cryptographic signature verification (CWE-347) in Red Hat Quay's Stripe billing webhook handler at the `/webhooks/stripe` endpoint. The handler accepts forged billing event requests in JSON format without validating the Stripe-Signature header, allowing unauthenticated attackers to send crafted requests. An attacker with network access to the endpoint can trigger unauthorized build quota resets and generate spurious billing notifications to administrators. The vulnerability exists even when the billing feature is disabled, though impact is reduced in self-hosted deployments using FakeStripe. Network-level mitigation is available by restricting access to the endpoint from untrusted sources.
Affected products
- Red Hat Quay <UNKNOWN>
Timeline
- 2026-08-14: disclosed