Remote Code Injection Vulnerability in Red Hat Quay
CVE-2026-74243

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
14 August 2026

What is CVE-2026-74243?

A security vulnerability in Red Hat Quay arises when the SECURITY_SCANNER_V4_PSK (pre-shared key) is not configured. This oversight allows unauthenticated remote attackers to exploit the security scanner notification endpoint by sending crafted POST requests. Such actions can lead to the flooding of the notification queue and the injection of path traversal characters into Clair API URL paths. Ultimately, this leads to resource exhaustion of the worker processes and allows for blind path manipulation on the Clair host, potentially resulting in a service disruption.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank meifukun (https://github.com/meifukun) for reporting this issue.
.