Red Hat Security Advisory: Red Hat Quay 3.9.18
Quay 3.9.18
AI Analysis
Technical Summary
CVE-2024-34156 is a vulnerability in the Go encoding/gob package where calling Decoder.Decode on messages with deeply nested structures can cause stack exhaustion and panic, resulting in denial of service. This is due to uncontrolled recursion in the decoding process. The issue affects Red Hat Quay versions >=3.9.0 and <3.9.18. Red Hat Quay 3.9.18 includes a fix for this vulnerability. The vulnerability has a CVSS v3 base score of 7.5 (high severity) as assessed by Red Hat, with an attack vector of network, low complexity, no privileges required, and no user interaction. The impact is high availability impact due to potential application crashes. No mitigation other than upgrading is currently available that meets Red Hat's criteria.
Potential Impact
The vulnerability can cause denial of service by crashing applications that decode maliciously crafted deeply nested gob messages, leading to stack exhaustion and panic. This can result in system unavailability or crashes, affecting the reliability and availability of services using the affected Go package within Red Hat Quay. There is no indication of confidentiality or integrity impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat recommends upgrading Red Hat Quay to version 3.9.18 or later, which includes the fix for this vulnerability. No other mitigation options meeting Red Hat's criteria for ease of use, applicability, and stability are currently available. Ensure all previously released errata relevant to your system are applied before updating. Monitor Red Hat advisories for any further updates.
Red Hat Security Advisory: Red Hat Quay 3.9.18
Description
Quay 3.9.18
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-34156 is a vulnerability in the Go encoding/gob package where calling Decoder.Decode on messages with deeply nested structures can cause stack exhaustion and panic, resulting in denial of service. This is due to uncontrolled recursion in the decoding process. The issue affects Red Hat Quay versions >=3.9.0 and <3.9.18. Red Hat Quay 3.9.18 includes a fix for this vulnerability. The vulnerability has a CVSS v3 base score of 7.5 (high severity) as assessed by Red Hat, with an attack vector of network, low complexity, no privileges required, and no user interaction. The impact is high availability impact due to potential application crashes. No mitigation other than upgrading is currently available that meets Red Hat's criteria.
Potential Impact
The vulnerability can cause denial of service by crashing applications that decode maliciously crafted deeply nested gob messages, leading to stack exhaustion and panic. This can result in system unavailability or crashes, affecting the reliability and availability of services using the affected Go package within Red Hat Quay. There is no indication of confidentiality or integrity impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat recommends upgrading Red Hat Quay to version 3.9.18 or later, which includes the fix for this vulnerability. No other mitigation options meeting Red Hat's criteria for ease of use, applicability, and stability are currently available. Ensure all previously released errata relevant to your system are applied before updating. Monitor Red Hat advisories for any further updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:2754
- Cve Count
- 12
- Additional Cves
- ["CVE-2024-45337","CVE-2024-45338","CVE-2025-12816","CVE-2025-52881","CVE-2025-61726","CVE-2025-61729","CVE-2025-65945","CVE-2025-66031","CVE-2025-66418","CVE-2025-66506","CVE-2026-24049"]
Threat ID: 6a160965e29bf47b5062a3db
Added to database: 05/26/2026, 20:58:13 UTC
Last enriched: 08/17/2026, 17:09:09 UTC
Last updated: 09/10/2026, 19:24:54 UTC
Views: 112
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.