Reflective Server-Side Request Forgery in Clair Impacting Red Hat Quay
CVE-2026-10517
5.8MEDIUM
What is CVE-2026-10517?
A vulnerability in Clair's fetcher component allows for potential Server-Side Request Forgery (SSRF) attacks. By making outbound HTTP requests to attacker-supplied URIs without proper IP or scheme filtering, an unauthenticated attacker can exploit this flaw when PSK authentication is not enforced. This could enable the attacker to relay malicious requests that may target internal services or cloud metadata endpoints, potentially leaking sensitive information through error messages. While operator-managed Red Hat Quay deployments are protected due to default PSK configuration, other setups may remain at risk.
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Martin Brodeur for reporting this issue.