Remote Code Injection Vulnerability in Red Hat Quay
CVE-2026-74243
6.5MEDIUM
What is CVE-2026-74243?
A security vulnerability in Red Hat Quay arises when the SECURITY_SCANNER_V4_PSK (pre-shared key) is not configured. This oversight allows unauthenticated remote attackers to exploit the security scanner notification endpoint by sending crafted POST requests. Such actions can lead to the flooding of the notification queue and the injection of path traversal characters into Clair API URL paths. Ultimately, this leads to resource exhaustion of the worker processes and allows for blind path manipulation on the Clair host, potentially resulting in a service disruption.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank meifukun (https://github.com/meifukun) for reporting this issue.