CVE-2026-2377
published 2026-04-08CVE-2026-2377: A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an…
PriorityP342medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.40%
32.7th percentile
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery (SSRF), could allow an attacker to send requests from the application's internal network, potentially leading to the disclosure of sensitive information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | mirror_registry_for_red_hat_openshift | — | — |
| redhat | quay | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Red Hat OpenShift mirror registry server-side request forgery (EUVD-2026-20507)
vuldb·2026-06-26·CVSS 6.5
CVE-2026-2377 [MEDIUM] Red Hat OpenShift mirror registry server-side request forgery (EUVD-2026-20507)
A vulnerability marked as critical has been reported in Red Hat OpenShift. This issue affects some unknown processing of the component mirror registry. Performing a manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-2377. The attack may be initiated remotely. There is no available exploit.
GHSA
GHSA-2c4x-699h-vw5x: A flaw was found in mirror-registry
ghsa_unreviewed·2026-04-08
CVE-2026-2377 [MEDIUM] CWE-918 GHSA-2c4x-699h-vw5x: A flaw was found in mirror-registry
A flaw was found in mirror-registry. Authenticated users can exploit the log export feature by providing a specially crafted web address (URL). This allows the application's backend to make arbitrary requests to internal network resources, a vulnerability known as Server-Side Request Forgery (SSRF). This could lead to unauthorized access to sensitive information or other internal systems.
Red Hat
mirror-registry: quay: quay: Server-Side Request Forgery via log export functionality
vendor_redhat·2026-04-08·CVSS 6.5
CVE-2026-2377 [MEDIUM] CWE-918 mirror-registry: quay: quay: Server-Side Request Forgery via log export functionality
mirror-registry: quay: quay: Server-Side Request Forgery via log export functionality
A flaw was found in mirror-registry. Authenticated users can exploit the log export feature by providing a specially crafted web address (URL). This allows the application's backend to make arbitrary requests to internal network resources, a vulnerability known as Server-Side Request Forgery (SSRF). This could lead to unauthorized access to sensitive information or other internal systems.
Statement: Due to the intended and supported use case of Openshift Mirror Registry, deployment in an offline or network-isolated environment, the impact for this product has been downgraded to `Moderate`.
Even in case of compromise, the blast radius is restricted to mirror-registry. It can not be escalated outside the
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:19375https://access.redhat.com/errata/RHSA-2026:21017https://access.redhat.com/errata/RHSA-2026:22629https://access.redhat.com/errata/RHSA-2026:22840https://access.redhat.com/errata/RHSA-2026:23361https://access.redhat.com/errata/RHSA-2026:24853https://access.redhat.com/security/cve/CVE-2026-2377https://bugzilla.redhat.com/show_bug.cgi?id=2439201https://access.redhat.com/errata/RHSA-2026:19375https://access.redhat.com/errata/RHSA-2026:21017https://access.redhat.com/errata/RHSA-2026:22629https://access.redhat.com/errata/RHSA-2026:22840https://access.redhat.com/errata/RHSA-2026:23361https://access.redhat.com/errata/RHSA-2026:24853https://access.redhat.com/security/cve/CVE-2026-2377https://bugzilla.redhat.com/show_bug.cgi?id=2439201https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2377.json
2026-04-08
Published