PT-2026-44761 · Red Hat · Quay

Osidb Bzimport

·

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2026-10052

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Quay (affected versions not specified)
Description A flaw exists in the LDAP and SMTP validation functions of the Quay config-tool. An attacker with config editor access can exploit these functions, which establish outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position to potentially map the internal network infrastructure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-10052

Affected Products

Quay