CVE-2026-32589
published 2026-04-08CVE-2026-32589: A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with…
PriorityP340medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.24%
15.4th percentile
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | mirror_registry_for_red_hat_openshift | — | — |
| redhat | quay | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7fjh-cgxv-cjc6: A flaw was found in Red Hat Quay's container image upload process
ghsa_unreviewed·2026-04-08
CVE-2026-32589 [HIGH] CWE-639 GHSA-7fjh-cgxv-cjc6: A flaw was found in Red Hat Quay's container image upload process
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.
Red Hat
mirror-registry: quay: insecure direct object reference in BlobUpload
vendor_redhat·2026-04-08·CVSS 7.1
CVE-2026-32589 [HIGH] CWE-639 mirror-registry: quay: insecure direct object reference in BlobUpload
mirror-registry: quay: insecure direct object reference in BlobUpload
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.
Statement: Exploitation requires valid login credentials to the Quay registry. Unauthenticated users cannot exploit this flaw.
Package: openshift/mirror-registry-rhel8 (mirror registry for Red Hat OpenShift) - Affected
Package: openshift/mirror-registry-rhel8 (mirror registry for Red Hat OpenShift 2) - Affected
Package: quay/quay-rhel8 (Red Hat Quay 3) - Affected
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:19375https://access.redhat.com/errata/RHSA-2026:21017https://access.redhat.com/errata/RHSA-2026:22465https://access.redhat.com/errata/RHSA-2026:22629https://access.redhat.com/errata/RHSA-2026:22840https://access.redhat.com/errata/RHSA-2026:23361https://access.redhat.com/errata/RHSA-2026:24853https://access.redhat.com/errata/RHSA-2026:28441https://access.redhat.com/security/cve/CVE-2026-32589https://bugzilla.redhat.com/show_bug.cgi?id=2446963https://access.redhat.com/errata/RHSA-2026:19375https://access.redhat.com/errata/RHSA-2026:21017https://access.redhat.com/errata/RHSA-2026:22465https://access.redhat.com/errata/RHSA-2026:22629https://access.redhat.com/errata/RHSA-2026:22840https://access.redhat.com/errata/RHSA-2026:23361https://access.redhat.com/errata/RHSA-2026:24853https://access.redhat.com/errata/RHSA-2026:28441https://access.redhat.com/security/cve/CVE-2026-32589https://bugzilla.redhat.com/show_bug.cgi?id=2446963https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32589.json
2026-04-08
Published