CVE-2026-32590

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

high 7.1 CVSS 3.1
Published: Apr 8, 2026
Modified: May 28, 2026
Vendor: Redhat
Product: Mirror Registry For Red Hat Openshift
Versions: 2.0,3.0.0

Description

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

References

Related CVEs