Security Advisory

CVE-2026-74247

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-14 22:43:15
Last updated 2026-08-14 22:43:15
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.