HIGHCVE-2026-32590Published Modified CNA redhat
CVE-2026-32590: Mirror-registry: remote code execution using pickle deserialization
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.
Metrics
- CVSS v3.1
- 7.1
- Severity
- HIGH
- Fixed in
- 1779204086
- Affected Products
- 4
Fix available
17792040861779689392
Affected packages
- Red Hat / Red Hat Quay 3.14Fixed in 1779689392
- Red Hat / Red Hat Quay 3.16Fixed in 1779204086
- Red Hat / mirror registry for Red Hat OpenShift
- Red Hat / mirror registry for Red Hat OpenShift 2
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H