Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.8epss 0.5%
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
nono source reports it
A flaw was found in Red Hat Quay's repository-level mirror configuration
feature. The POST and PUT handlers in endpoints/api/mirror.py accept an
external_reference parameter without SSRF validation, unlike the
organization-level mirror handlers which apply validate_external_registry_url().
A repository administrator can supply a crafted hostname that causes the Quay
mirror worker to make requests via Skopeo to internal network services, cloud
metadata endpoints, or other resources not intended to be reachable from the
Quay application.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected products
Red Hat · mirror registry for Red Hat OpenShift 2Red Hat · Red Hat Quay 3.10Red Hat · Red Hat Quay 3.12Red Hat · Red Hat Quay 3.15Red Hat · Red Hat Quay 3.17Red Hat · Red Hat Quay 3.9References
https://access.redhat.com/errata/RHSA-2026:50931https://access.redhat.com/errata/RHSA-2026:52968https://access.redhat.com/errata/RHSA-2026:53520https://access.redhat.com/errata/RHSA-2026:54395https://access.redhat.com/errata/RHSA-2026:63307https://access.redhat.com/security/cve/CVE-2026-15927https://bugzilla.redhat.com/show_bug.cgi?id=2501256