Red hat quay 3
This hub aggregates every CVE we track for Red hat quay 3, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM15HIGH3LOW1
Monthly trend
0
3
0
0
0
1
0
0
1
0
0
0
0
0
0
0
0
0
1
1
2
1
4
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat quay 3.
- CVE-2026-18255Quay: quay: global read-only superuser can view robot account tokens7.2
- CVE-2026-16910Quay: ssrf in red hat quay notification webhooks (slack/generic)5.5
- CVE-2026-15927Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation6.8
- CVE-2026-16254Claircore: claircore: denial of service via out-of-bounds slice in claircore's apk installed-database parser4.3
- CVE-2026-11569Quay: quay: stored xss via filedrop svg upload5.4
- CVE-2026-10078Quay/config-tool: quay/config-tool: gitlab oauth client_secret exposed in url querystring2.7
- CVE-2026-10052Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config validation endpoints4.1
- CVE-2026-6848Quay: red hat quay: authentication bypass allows privileged actions without valid credentials5.4
- CVE-2026-2376Mirror-registry: quay: quay: server-side request forgery via open redirect vulnerability in web interface4.9
- CVE-2025-4374Quay: incorrect privilege assignment6.5
- CVE-2024-11831Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript5.4
- CVE-2024-9683Quay: quay allows successful authentication with trucated version of the password4.8
- CVE-2024-9676Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)6.5
- CVE-2024-9675Buildah: buildah allows arbitrary directory mount7.8
- CVE-2024-5891Quay: unauthorized user may authenticate via oauth application token4.2
Product normalization is registry-driven with AI assist and human review. How it works