A flaw was found in quay-builder-qemu. (CVE-2026-85469)
A vulnerability exists in quay-builder-qemu due to the use of a mutable third-party GitHub Action in its release workflow. This flaw allows a remote attacker to inject arbitrary code by compromising the upstream Noelware/docker-manifest-action pinned to a mutable branch. Exploitation can lead to exfiltration of sensitive registry credentials or publication of malicious container images. The workflow also exposes the default GitHub token, increasing the severity of the compromise. No official patch or mitigation currently meets Red Hat's criteria for deployment.
AI Analysis
Technical Summary
The quay-builder-qemu component in Red Hat Quay uses a release workflow that incorporates the third-party GitHub Action Noelware/docker-manifest-action pinned to a mutable branch (@master). This introduces a supply chain vulnerability where a remote attacker can compromise the upstream action to inject arbitrary code. Such code injection can result in exfiltration of sensitive registry credentials (including Quay push tokens) or the publication of malicious container images, undermining the integrity of images consumed by Red Hat Quay build executors. Additionally, the workflow exposes the default GitHub token, further increasing the risk. Red Hat has classified this as an important supply chain vulnerability with a high CVSS v3.1 score of 8.0, reflecting high impact on confidentiality, integrity, and availability. Currently, no mitigation or patch is available that meets Red Hat's standards for ease of use, applicability, or stability.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code within the build workflow, leading to exfiltration of sensitive registry credentials and the potential publication of malicious container images. This compromises the integrity and confidentiality of container images built and distributed via Red Hat Quay, potentially affecting downstream consumers. The exposure of the default GitHub token further elevates the risk by enabling broader unauthorized access within the GitHub environment.
Mitigation Recommendations
As per the Red Hat advisory, no mitigation or patch currently meets the criteria for deployment. Users should monitor Red Hat advisories for updates. Until a fix or effective mitigation is available, organizations should consider restricting access to the affected workflows and carefully review the use of third-party GitHub Actions pinned to mutable branches in their CI/CD pipelines.
A flaw was found in quay-builder-qemu. (CVE-2026-85469)
Description
A vulnerability exists in quay-builder-qemu due to the use of a mutable third-party GitHub Action in its release workflow. This flaw allows a remote attacker to inject arbitrary code by compromising the upstream Noelware/docker-manifest-action pinned to a mutable branch. Exploitation can lead to exfiltration of sensitive registry credentials or publication of malicious container images. The workflow also exposes the default GitHub token, increasing the severity of the compromise. No official patch or mitigation currently meets Red Hat's criteria for deployment.
CVSS v3.1
Score 8.0high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The quay-builder-qemu component in Red Hat Quay uses a release workflow that incorporates the third-party GitHub Action Noelware/docker-manifest-action pinned to a mutable branch (@master). This introduces a supply chain vulnerability where a remote attacker can compromise the upstream action to inject arbitrary code. Such code injection can result in exfiltration of sensitive registry credentials (including Quay push tokens) or the publication of malicious container images, undermining the integrity of images consumed by Red Hat Quay build executors. Additionally, the workflow exposes the default GitHub token, further increasing the risk. Red Hat has classified this as an important supply chain vulnerability with a high CVSS v3.1 score of 8.0, reflecting high impact on confidentiality, integrity, and availability. Currently, no mitigation or patch is available that meets Red Hat's standards for ease of use, applicability, or stability.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code within the build workflow, leading to exfiltration of sensitive registry credentials and the potential publication of malicious container images. This compromises the integrity and confidentiality of container images built and distributed via Red Hat Quay, potentially affecting downstream consumers. The exposure of the default GitHub token further elevates the risk by enabling broader unauthorized access within the GitHub environment.
Mitigation Recommendations
As per the Red Hat advisory, no mitigation or patch currently meets the criteria for deployment. Users should monitor Red Hat advisories for updates. Until a fix or effective mitigation is available, organizations should consider restricting access to the affected workflows and carefully review the use of third-party GitHub Actions pinned to mutable branches in their CI/CD pipelines.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8ghx-8455-hgv5
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-85469"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aab494555bf5e2cf5990404
Added to database: 09/17/2026, 01:58:29 UTC
Last enriched: 09/17/2026, 02:02:46 UTC
Last updated: 09/17/2026, 02:02:46 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.