Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.8
CVE-2026-15927: Red Hat Quay: Malicious Mirror Configuration Can Expose Internal Services
CVE-2026-15927
CVE-2026-15927
Summary
A security flaw in Red Hat Quay's mirror configuration feature allows an attacker to trick the system into accessing internal network services or cloud metadata endpoints that should not be reachable. This could potentially expose sensitive information or disrupt the system. To mitigate this risk, administrators should update their Red Hat Quay setup to the latest version, which includes fixes for this vulnerability.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | mirror registry for red hat openshift 2 | All versions |
| red hat | red hat quay 3 | All versions |
Original title
Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation
Original description
A flaw was found in Red Hat Quay's repository-level mirror configuration
feature. The POST and PUT handlers in endpoints/api/mirror.py accept an
external_reference parameter without SSRF validation, unlike the
organization-level mirror handlers which apply validate_external_registry_url().
A repository administrator can supply a crafted hostname that causes the Quay
mirror worker to make requests via Skopeo to internal network services, cloud
metadata endpoints, or other resources not intended to be reachable from the
Quay application.
feature. The POST and PUT handlers in endpoints/api/mirror.py accept an
external_reference parameter without SSRF validation, unlike the
organization-level mirror handlers which apply validate_external_registry_url().
A repository administrator can supply a crafted hostname that causes the Quay
mirror worker to make requests via Skopeo to internal network services, cloud
metadata endpoints, or other resources not intended to be reachable from the
Quay application.
nvd CVSS3.1
6.8
Vulnerability type
CWE-918
Server-Side Request Forgery (SSRF)
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026