Flaw in LDAP and SMTP Validation in Quay Config-Tool
CVE-2026-10052

4.1MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
29 May 2026

What is CVE-2026-10052?

A vulnerability exists in the Quay config-tool related to its LDAP and SMTP validation functions. This flaw enables an attacker with config editor access to exploit these functions, allowing them to make outbound connections to user-supplied endpoints without appropriate IP or host filtering. As a result, an attacker can conduct internal network reconnaissance from the Quay pod's network position, potentially enabling mapping of the internal network infrastructure.

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Martin Brodeur for reporting this issue.
.