Cross-Site Scripting Flaw in Quay Auth Handler
CVE-2026-102295

5.4MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
5 October 2026

What is CVE-2026-102295?

A vulnerability exists in Quay due to an improper implementation in the OAuth callback handler, which exposes users to cross-site scripting (XSS) attacks. By deceiving a logged-in user into clicking a malicious link, an attacker can exploit this vulnerability to execute arbitrary JavaScript in the user's browser session. The exploitation could lead to session hijacking, unauthorized access to sensitive user data, or illicit actions conducted under the victim's credentials.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Shashank (CredShields) for reporting this issue.
.