A flaw was found in Red Hat Quay's Stripe billing webhook handler. (CVE-2026-74244)
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators.
AI Analysis
Technical Summary
CVE-2026-74244 is a moderate severity vulnerability in Red Hat Quay's Stripe billing webhook handler caused by missing validation of the Stripe-Signature header. This allows unauthenticated attackers to forge billing events by sending crafted JSON requests to the /webhooks/stripe endpoint. Successful exploitation can lead to unauthorized resetting of a namespace's build quota to its maximum and cause unsolicited billing emails to be sent to namespace administrators. The vulnerability is present even when billing is disabled but has reduced impact in self-hosted deployments using FakeStripe. The vulnerability is classified under CWE-347 (Improper Verification of Cryptographic Signature). No official patch is currently available, and mitigation relies on network-level access restrictions.
Potential Impact
An attacker can forge billing events without authentication, leading to unauthorized resetting of build quotas to maximum values and triggering unsolicited billing emails to namespace administrators. This impacts resource availability and user experience but does not affect confidentiality or availability directly. The vulnerability does not require user interaction and has a high integrity impact but no confidentiality or availability impact.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. To mitigate the risk, restrict network access to the /webhooks/stripe endpoint by configuring firewalls to allow connections only from trusted Stripe IP addresses. If Stripe billing integration is not used, block access to this endpoint entirely. Apply and verify network changes carefully, noting that service restarts or reloads may temporarily impact Red Hat Quay availability.
A flaw was found in Red Hat Quay's Stripe billing webhook handler. (CVE-2026-74244)
Description
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators.
CVSS v3.1
Score 5.9medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-74244 is a moderate severity vulnerability in Red Hat Quay's Stripe billing webhook handler caused by missing validation of the Stripe-Signature header. This allows unauthenticated attackers to forge billing events by sending crafted JSON requests to the /webhooks/stripe endpoint. Successful exploitation can lead to unauthorized resetting of a namespace's build quota to its maximum and cause unsolicited billing emails to be sent to namespace administrators. The vulnerability is present even when billing is disabled but has reduced impact in self-hosted deployments using FakeStripe. The vulnerability is classified under CWE-347 (Improper Verification of Cryptographic Signature). No official patch is currently available, and mitigation relies on network-level access restrictions.
Potential Impact
An attacker can forge billing events without authentication, leading to unauthorized resetting of build quotas to maximum values and triggering unsolicited billing emails to namespace administrators. This impacts resource availability and user experience but does not affect confidentiality or availability directly. The vulnerability does not require user interaction and has a high integrity impact but no confidentiality or availability impact.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. To mitigate the risk, restrict network access to the /webhooks/stripe endpoint by configuring firewalls to allow connections only from trusted Stripe IP addresses. If Stripe billing integration is not used, block access to this endpoint entirely. Apply and verify network changes carefully, noting that service restarts or reloads may temporarily impact Red Hat Quay availability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fgq8-mwjv-6335
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74244"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7ff5e6bf8831d53987df60
Added to database: 08/15/2026, 05:15:18 UTC
Last enriched: 08/15/2026, 06:14:23 UTC
Last updated: 08/15/2026, 23:41:00 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.