PT-2026-64254 · Red Hat · Red Hat Openshift Update Service+1

CVE-2026-16910

·

Publicado

2026-07-24

·

Atualizado

2026-07-24

CVSS v3.1

5.5

Média

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-16910

Produtos afetados

Red Hat Openshift Update Service
Red Hat Quay 3