CVE-2026-32591
published 2026-04-08CVE-2026-32591: A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching…
PriorityP335medium5.5CVSS 3.1
AVNACLPRHUINSUCHILAN
EPSS
0.27%
18.7th percentile
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization administrator privileges could supply a crafted hostname to force the Quay server to make requests to internal network services, cloud infrastructure endpoints, or other resources that should not be accessible from the Quay application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | mirror_registry_for_red_hat_openshift | — | — |
| redhat | quay | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
vendor_redhat5.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
vendor_redhat·2026-04-08·CVSS 5.2
CVE-2026-32591 [MEDIUM] CWE-918 mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization administrator privileges could supply a crafted hostname to force the Quay server to make requests to internal network services, cloud infrastructure endpoints, or other resources that should not be accessible from the Quay application.
Statement: Exploitation requires the attacker to be authenticated as an organization administrator.
Package: openshift/mirror-registry-rhel8 (
GHSA
GHSA-9wjq-f6rc-86wf: A flaw was found in Red Hat Quay's Proxy Cache configuration feature
ghsa_unreviewed·2026-04-08
CVE-2026-32591 [MEDIUM] CWE-918 GHSA-9wjq-f6rc-86wf: A flaw was found in Red Hat Quay's Proxy Cache configuration feature
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization administrator privileges could supply a crafted hostname to force the Quay server to make requests to internal network services, cloud infrastructure endpoints, or other resources that should not be accessible from the Quay application.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:24833https://access.redhat.com/errata/RHSA-2026:40262https://access.redhat.com/errata/RHSA-2026:41031https://access.redhat.com/errata/RHSA-2026:41066https://access.redhat.com/security/cve/CVE-2026-32591https://bugzilla.redhat.com/show_bug.cgi?id=2446965https://access.redhat.com/errata/RHSA-2026:24833https://access.redhat.com/errata/RHSA-2026:40262https://access.redhat.com/errata/RHSA-2026:41031https://access.redhat.com/errata/RHSA-2026:41066https://access.redhat.com/security/cve/CVE-2026-32591https://bugzilla.redhat.com/show_bug.cgi?id=2446965https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32591.json
2026-04-08
Published