CVE-2026-15927
MEDIUMQuay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation
Title source: cnaDescription
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.
References (2)
Core 2
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-15927
Issue Tracking, X_Refsource_Redhat issue-tracking
x_refsource_redhat
RHBZ#2501256
https://bugzilla.redhat.com/show_bug.cgi?id=2501256
Scores
CVSS v3
6.8
EPSS
0.0023
EPSS Percentile
14.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (2)
Red Hat/mirror registry for Red Hat OpenShift 2
Red Hat/Red Hat Quay 3
Published
Jul 21, 2026
Tracked Since
Jul 21, 2026