CVE-2026-74243
published 2026-08-14CVE-2026-74243: A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the…
PriorityP349high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.27%
18.3th percentile
A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths. The primary consequence is worker resource exhaustion and blind path manipulation on the configured Clair host, potentially leading to a denial of service.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openshift-update-service | openshift-update-service-rhel8 | — | — |
| quay | quay-rhel8 | — | — |
| quay | quay-rhel9 | — | — |
| redhat | quay | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
quay: Unauthenticated secscan notification endpoint in Quay when PSK is unset
vendor_redhat·2026-08-14·CVSS 6.5
CVE-2026-74243 [MEDIUM] CWE-306 quay: Unauthenticated secscan notification endpoint in Quay when PSK is unset
quay: Unauthenticated secscan notification endpoint in Quay when PSK is unset
A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths. The primary consequence is worker resource exhaustion and blind path manipulation on the configured Clair host, potentially leading to a denial of service.
Statement: Moderate: This flaw in Red Hat Quay allows unauthenticated attackers to flood the security scanner notification endpoint, potentially leading to worker resource exhaustion and blind path manipulation on the configured Clair host. Thi
VulDB
Red Hat OpenShift Update Service/Quay Security Scanner Notification Endpoint path traversal
vuldb·2026-08-15·CVSS 6.5
CVE-2026-74243 [MEDIUM] Red Hat OpenShift Update Service/Quay Security Scanner Notification Endpoint path traversal
A vulnerability, which was classified as critical, has been found in Red Hat OpenShift Update Service and Quay. This affects an unknown part of the component Security Scanner Notification Endpoint. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-74243. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
A flaw was found in Red Hat Quay.
ghsa_unreviewed·2026-08-15
CVE-2026-74243 [MEDIUM] CWE-306 A flaw was found in Red Hat Quay.
A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths. The primary consequence is worker resource exhaustion and blind path manipulation on the configured Clair host, potentially leading to a denial of service.
No detection rules found.
No public exploits indexed.
2026-08-14
Published