CVE-2026-74247
published 2026-08-14CVE-2026-74247: A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF)…
PriorityP344high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.14%
4.0th percentile
A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openshift-update-service | openshift-update-service-rhel8 | — | — |
| quay | quay-rhel8 | — | — |
| quay | quay-rhel9 | — | — |
| redhat | quay | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
quay: SSRF via build archive_url in Quay build API
vendor_redhat·2026-08-14·CVSS 4.2
CVE-2026-74247 [MEDIUM] CWE-918 quay: SSRF via build archive_url in Quay build API
quay: SSRF via build archive_url in Quay build API
A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.
Statement: This Moderate impact flaw in Red Hat Quay's build API allows an authenticated user with repository write access and the `FEATURE_BUILD_SUPPORT` feature enabled to perform Server-Side Request Forgery (SSRF) attacks. Exploitation requires specific configuration and privileges, limiting the attack surface. Successful exploitation could enable acce
GHSA
A flaw was found in Red Hat Quay.
ghsa_unreviewed·2026-08-15
CVE-2026-74247 [MEDIUM] CWE-918 A flaw was found in Red Hat Quay.
A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.
VulDB
Red Hat Quay Build API server-side request forgery
vuldb·2026-08-15·CVSS 4.2
CVE-2026-74247 [MEDIUM] Red Hat Quay Build API server-side request forgery
A vulnerability was found in Red Hat Quay and classified as problematic. Impacted is an unknown function of the component Build API. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-74247. The attack can be launched remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
2026-08-14
Published