Skip to main content

A flaw was found in quay-builder-qemu. (CVE-2026-85469)

0
High
Published: 09/17/2026 (09/17/2026, 00:31:25 UTC)
Source: GCVE Database

Description

A vulnerability exists in quay-builder-qemu due to the use of a mutable third-party GitHub Action in its release workflow. This flaw allows a remote attacker to inject arbitrary code by compromising the upstream Noelware/docker-manifest-action pinned to a mutable branch. Exploitation can lead to exfiltration of sensitive registry credentials or publication of malicious container images. The workflow also exposes the default GitHub token, increasing the severity of the compromise. No official patch or mitigation currently meets Red Hat's criteria for deployment.

CVSS v3.1

Score 8.0high

Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 02:02:46 UTC

Technical Analysis

The quay-builder-qemu component in Red Hat Quay uses a release workflow that incorporates the third-party GitHub Action Noelware/docker-manifest-action pinned to a mutable branch (@master). This introduces a supply chain vulnerability where a remote attacker can compromise the upstream action to inject arbitrary code. Such code injection can result in exfiltration of sensitive registry credentials (including Quay push tokens) or the publication of malicious container images, undermining the integrity of images consumed by Red Hat Quay build executors. Additionally, the workflow exposes the default GitHub token, further increasing the risk. Red Hat has classified this as an important supply chain vulnerability with a high CVSS v3.1 score of 8.0, reflecting high impact on confidentiality, integrity, and availability. Currently, no mitigation or patch is available that meets Red Hat's standards for ease of use, applicability, or stability.

Potential Impact

Successful exploitation allows remote attackers to execute arbitrary code within the build workflow, leading to exfiltration of sensitive registry credentials and the potential publication of malicious container images. This compromises the integrity and confidentiality of container images built and distributed via Red Hat Quay, potentially affecting downstream consumers. The exposure of the default GitHub token further elevates the risk by enabling broader unauthorized access within the GitHub environment.

Mitigation Recommendations

As per the Red Hat advisory, no mitigation or patch currently meets the criteria for deployment. Users should monitor Red Hat advisories for updates. Until a fix or effective mitigation is available, organizations should consider restricting access to the affected workflows and carefully review the use of third-party GitHub Actions pinned to mutable branches in their CI/CD pipelines.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-8ghx-8455-hgv5
Osv Schema Version
1.4.0
Aliases
["CVE-2026-85469"]
Database Specific Severity
HIGH
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aab494555bf5e2cf5990404

Added to database: 09/17/2026, 01:58:29 UTC

Last enriched: 09/17/2026, 02:02:46 UTC

Last updated: 09/17/2026, 02:02:46 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses