Skip to main content
EPSS 2.1%top 19%

Red Hat Security Advisory: Red Hat Quay 3.9.19

0
High
Published: 03/19/2026 (03/19/2026, 19:18:06 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Quay 3.9.19

Affected software

Affected versions
=3.9.19Red HatRed Hat QuayRed Hat Quay 3.9amd64registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:3443ae24c14bfe47730a8c9d80478948df7364eb5a11c031537d6a1ec39aac8d_amd64Red Hat OpenStack PlatformRed Hat OpenStack Platform 16.2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 19:32:23 UTC

Technical Analysis

CVE-2025-61726 is a vulnerability in the Go net/url package where no limit is enforced on the number of unique query parameters parsed by net/http.Request.ParseForm. An attacker can craft an HTTP request with a large number of unique query parameters, causing excessive memory consumption and resulting in a denial of service by crashing or hanging the application. This affects applications using this Go package, including Red Hat Quay 3.9.19. The vulnerability impacts availability only, with no confidentiality or integrity impact. Red Hat rates this vulnerability as important (high severity) and recommends updating the affected package. No practical mitigation other than updating is available. The vulnerability is tracked under CWE-770 (Allocation of Resources Without Limits or Throttling).

Potential Impact

Successful exploitation results in denial of service due to excessive memory consumption when parsing a large number of unique query parameters in HTTP requests. This causes the affected application to crash or become unresponsive, impacting availability. There is no impact on confidentiality or integrity.

Mitigation Recommendations

Red Hat advises updating to the fixed version of Red Hat Quay 3.9.19 as soon as possible. No practical mitigation other than applying the update has been identified. Ensure all previously released errata relevant to your system are applied before updating. Monitor Red Hat advisories for any further updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:5168
Cve Count
10
Additional Cves
["CVE-2025-68121","CVE-2025-69873","CVE-2026-25639","CVE-2026-25990","CVE-2026-26007","CVE-2026-26996","CVE-2026-27628","CVE-2026-27904","CVE-2026-28802"]
State
PUBLISHED

Threat ID: 6a160965e29bf47b5062b0c5

Added to database: 05/26/2026, 20:58:13 UTC

Last enriched: 08/14/2026, 19:32:23 UTC

Last updated: 09/13/2026, 10:01:28 UTC

Views: 124

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses