Cross-Site Scripting Vulnerability in Quay by Red Hat
CVE-2026-102576
4.2MEDIUM
What is CVE-2026-102576?
A flaw exists in Quay that allows a remote attacker to manipulate login processes. By crafting specially designed links, an attacker could persuade users to log in through these URLs. If successful, this could lead to the execution of arbitrary scripts in the context of the users' authenticated sessions. This issue arises because the application fails to validate the redirect destination prior to navigating, exposing users on Quay who rely on direct database authentication to potential XSS attacks.
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Shashank (CredShields) for reporting this issue.