CVE-2026-2376
published 2026-03-12CVE-2026-2376: A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.16%
5.2th percentile
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses.
When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | quay | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9w78-x9jw-9c7m: A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by provi
ghsa_unreviewed·2026-03-12
CVE-2026-2376 [MEDIUM] CWE-601 GHSA-9w78-x9jw-9c7m: A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by provi
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses.
When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.
Red Hat
mirror-registry: quay: quay: Server-side Request Forgery via open redirect vulnerability in web interface
vendor_redhat·2026-03-03·CVSS 4.9
CVE-2026-2376 [MEDIUM] CWE-601 mirror-registry: quay: quay: Server-side Request Forgery via open redirect vulnerability in web interface
mirror-registry: quay: quay: Server-side Request Forgery via open redirect vulnerability in web interface
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses.
When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses.
When the application processes these addresses, it automatically follows redirects without verifying the final destination, allo
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-12
Published