Executive brief
Red Hat Quay is a container image registry used by enterprises to store and manage container images. A vulnerability in Quay's build API allows authenticated users with repository write access to craft malicious URLs that trick the Quay builder into making requests to internal network systems, potentially exposing sensitive internal information or credentials. The attack requires the build feature to be enabled and user authentication, limiting but not eliminating the risk.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) flaw in Red Hat Quay's build API that allows authenticated users to supply a malicious archive_url parameter. When a user with FEATURE_BUILD_SUPPORT enabled and repository write access provides a crafted URL, the Quay builder processes the request and makes outbound connections to attacker-specified internal network addresses. The attacker can bypass network-based access controls and access internal services, metadata endpoints, or services running on localhost. Exploitation requires prior authentication and repository write permissions, but no user interaction from other parties is required. Red Hat rates this as moderate severity (CVSS 4.2); the mitigation is to disable FEATURE_BUILD_SUPPORT if not needed.
Affected products
- Red Hat Quay
Timeline
- 2026-08-14: disclosed