Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.8

CVE-2026-15927: Red Hat Quay: Malicious Mirror Configuration Can Expose Internal Services

CVE-2026-15927 CVE-2026-15927
Summary

A security flaw in Red Hat Quay's mirror configuration feature allows an attacker to trick the system into accessing internal network services or cloud metadata endpoints that should not be reachable. This could potentially expose sensitive information or disrupt the system. To mitigate this risk, administrators should update their Red Hat Quay setup to the latest version, which includes fixes for this vulnerability.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
red hat mirror registry for red hat openshift 2 All versions
red hat red hat quay 3 All versions
Original title
Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation
Original description
A flaw was found in Red Hat Quay's repository-level mirror configuration
feature. The POST and PUT handlers in endpoints/api/mirror.py accept an
external_reference parameter without SSRF validation, unlike the
organization-level mirror handlers which apply validate_external_registry_url().
A repository administrator can supply a crafted hostname that causes the Quay
mirror worker to make requests via Skopeo to internal network services, cloud
metadata endpoints, or other resources not intended to be reachable from the
Quay application.
nvd CVSS3.1 6.8
Vulnerability type
CWE-918 Server-Side Request Forgery (SSRF)
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026