PT-2026-47274 · Red Hat · Quay

Toni Gornals

·

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2026-11569

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Quay (affected versions not specified)
Description A flaw exists in the 'filedrop' endpoint that accepts any mime type without validation. This allows an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. Because the file is stored and served inline through the CDN, it enables stored cross-site scripting (XSS), which is a technique where a malicious script is permanently stored on the target server and executed when a victim visits the archive URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-11569

Affected Products

Quay