CVE-2026-74244
published 2026-08-14CVE-2026-74244: A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.14%
3.8th percentile
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openshift-update-service | openshift-update-service-rhel8 | — | — |
| quay | quay-rhel8 | — | — |
| quay | quay-rhel9 | — | — |
| redhat | quay | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
quay: Stripe webhook accepts forged events without signature verification in Quay
vendor_redhat·2026-08-14·CVSS 5.9
CVE-2026-74244 [MEDIUM] CWE-347 quay: Stripe webhook accepts forged events without signature verification in Quay
quay: Stripe webhook accepts forged events without signature verification in Quay
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators.
Statement: This Moderate flaw in Red Hat Quay's Stripe billing webhook handler allows unauthenticated attackers to forge billing events due to missing signature validation. This can lead to unauthorized build quota resets and unsolicited billing emails to namespace administrators
VulDB
Red Hat OpenShift Update Service/Quay Stripe Billing Webhook /webhooks/stripe improper authentication
vuldb·2026-08-15·CVSS 5.9
CVE-2026-74244 [MEDIUM] Red Hat OpenShift Update Service/Quay Stripe Billing Webhook /webhooks/stripe improper authentication
A vulnerability has been found in Red Hat OpenShift Update Service and Quay and classified as problematic. This issue affects some unknown processing of the file /webhooks/stripe of the component Stripe Billing Webhook Handler. Performing a manipulation results in improper authentication.
This vulnerability is identified as CVE-2026-74244. The attack can be initiated remotely. There is not any exploit available.
GHSA
A flaw was found in Red Hat Quay's Stripe billing webhook handler.
ghsa_unreviewed·2026-08-15
CVE-2026-74244 [MEDIUM] CWE-347 A flaw was found in Red Hat Quay's Stripe billing webhook handler.
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators.
No detection rules found.
No public exploits indexed.
2026-08-14
Published