Flaw in LDAP and SMTP Validation in Quay Config-Tool
CVE-2026-10052
4.1MEDIUM
What is CVE-2026-10052?
A vulnerability exists in the Quay config-tool related to its LDAP and SMTP validation functions. This flaw enables an attacker with config editor access to exploit these functions, allowing them to make outbound connections to user-supplied endpoints without appropriate IP or host filtering. As a result, an attacker can conduct internal network reconnaissance from the Quay pod's network position, potentially enabling mapping of the internal network infrastructure.
References
CVSS V3.1
Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Martin Brodeur for reporting this issue.