HarborGuard / CVE
Back to search
HIGHCVE-2026-32590Published Modified CNA redhat

CVE-2026-32590: Mirror-registry: remote code execution using pickle deserialization

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

Metrics

CVSS v3.1
7.1
Severity
HIGH
Fixed in
1779204086
Affected Products
4

Fix available

17792040861779689392
Affected packages
  • Red Hat / Red Hat Quay 3.14
    Fixed in 1779689392
  • Red Hat / Red Hat Quay 3.16
    Fixed in 1779204086
  • Red Hat / mirror registry for Red Hat OpenShift
  • Red Hat / mirror registry for Red Hat OpenShift 2
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H