Junglewise Threat Intelligence

CVE-2026-74244: Red Hat Quay Stripe webhook signature validation bypass

CVE-2026-74244 · Severity: medium · CVSS 5.9 · Published 2026-08-14

Technologies: Red Hat Quay config-tool, Redhat Quay. Vendors: Red Hat, Redhat.

Executive brief

Red Hat Quay is a container image registry platform used by enterprises to store and manage container images. An attacker can exploit a flaw in its billing webhook handler to forge fake billing events without proper verification, potentially resetting namespace build quotas to maximum and sending unsolicited billing emails to administrators, disrupting resource management and user operations.

Technical details

The vulnerability is an improper cryptographic signature verification (CWE-347) in Red Hat Quay's Stripe billing webhook handler at the `/webhooks/stripe` endpoint. The handler accepts forged billing event requests in JSON format without validating the Stripe-Signature header, allowing unauthenticated attackers to send crafted requests. An attacker with network access to the endpoint can trigger unauthorized build quota resets and generate spurious billing notifications to administrators. The vulnerability exists even when the billing feature is disabled, though impact is reduced in self-hosted deployments using FakeStripe. Network-level mitigation is available by restricting access to the endpoint from untrusted sources.

Affected products

  • Red Hat Quay <UNKNOWN>

Timeline

  • 2026-08-14: disclosed

References

Related threats