Proxy Cache Configuration Flaw in Red Hat Quay
CVE-2026-32591
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-32591?
A vulnerability exists in Red Hat Quay related to the Proxy Cache configuration feature. When administrators set up an upstream registry for proxy caching, the application establishes a network connection to the designated hostname without validating its legitimacy. This flaw allows attackers with organization administrator privileges to exploit the system by supplying a malicious hostname. Consequently, the Quay server may inadvertently interact with internal network services or unauthorized cloud infrastructure endpoints, leading to potential exposure of sensitive resources that should remain inaccessible.
Affected Version(s)
Red Hat Quay 3.1 1783750447
Red Hat Quay 3.12 1783751865
Red Hat Quay 3.15 1784351966
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved