Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.4%top 66%

Red Hat Security Advisory: Red Hat Quay 3.17.3

0
High
Published: 06/09/2026 (06/09/2026, 13:57:35 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Quay 3.17.3

Affected software

Affected versions
>=3.17.0 <3.17.3Red HatRed Hat QuayRed Hat Quay 3.17amd64registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:c7827fe2034ee2d88d5cc9365f3f8ecc88431f2559742c48f7819ed08ba59763_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 19:41:11 UTC

Technical Analysis

A vulnerability (CVE-2026-32590) exists in Red Hat Quay's handling of resumable container image layer uploads where intermediate upload data is stored in a database using a format susceptible to tampering. This insecure deserialization (CWE-502) could enable an attacker with valid login credentials to execute arbitrary code on the Quay server. Exploitation requires authentication via the web interface or container tools like Podman. The vulnerability is fixed in Red Hat Quay 3.17.3. The issue is tracked under Red Hat advisory RHSA-2026:24833 and is rated as high severity by Red Hat.

Potential Impact

An authenticated attacker with valid credentials can exploit this vulnerability to execute arbitrary code on the Red Hat Quay server. This could lead to full compromise of the registry service, affecting confidentiality, integrity, and availability of the system. The vulnerability requires low privileges but high attack complexity due to the need for authentication and specific conditions. No known exploits in the wild have been reported.

Mitigation Recommendations

Red Hat has released Red Hat Quay version 3.17.3 which fixes this vulnerability. Users should apply this update after ensuring all previously released errata relevant to their system have been applied. Exploitation requires authentication, so ensuring strong credential management and access controls is also recommended. No additional mitigations are noted in the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:24833
Cve Count
2
Additional Cves
["CVE-2026-32591"]
Cvss Version
3.1

Threat ID: 6a3c0cf8eed863c81e23a52e

Added to database: 06/24/2026, 16:59:36 UTC

Last enriched: 08/12/2026, 19:41:11 UTC

Last updated: 09/04/2026, 10:52:08 UTC

Views: 48

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses