Quay
This hub aggregates every CVE we track for Quay, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
OSS Librariesother
31
CVEs tracked
2
Critical
12
High
1
In CISA KEV
Severity distribution
MEDIUM17HIGH12CRITICAL2
Monthly trend
0
0
0
1
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
5
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Quay.
- CVE-2026-6848Quay: red hat quay: authentication bypass allows privileged actions without valid credentials5.4
- CVE-2026-32591Mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration5.2
- CVE-2026-32590Mirror-registry: remote code execution using pickle deserialization7.1
- CVE-2026-32589Mirror-registry: quay: insecure direct object reference in blobupload7.4
- CVE-2026-2377Mirror-registry: quay: quay: server-side request forgery via log export functionality6.5
- CVE-2026-2376Mirror-registry: quay: quay: server-side request forgery via open redirect vulnerability in web interface4.9
- CVE-2025-4374Quay: incorrect privilege assignment6.5
- CVE-2024-9683Quay: quay allows successful authentication with trucated version of the password4.8
- CVE-2024-5891Quay: unauthorized user may authenticate via oauth application token4.2
- CVE-2023-4956Quay: clickjacking on config-editor page severity6.5
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.KEV7.5
- CVE-2023-4959Quay: cross-site request forgery (csrf) on config-editor page6.5
- CVE-2023-3384Quay: stored cross site scripting5.4
- CVE-2020-10735A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s f...7.5
- CVE-2022-2447A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This coul...6.6
Product normalization is registry-driven with AI assist and human review. How it works