CVE-2026-15927

MEDIUM

Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation

Title source: cna
STIX 2.1

Description

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.

References (2)

Core 2
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-15927
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2501256
https://bugzilla.redhat.com/show_bug.cgi?id=2501256

Scores

CVSS v3 6.8
EPSS 0.0023
EPSS Percentile 14.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
Red Hat/mirror registry for Red Hat OpenShift 2
Red Hat/Red Hat Quay 3
Published Jul 21, 2026
Tracked Since Jul 21, 2026