VDB
CVE-2026-32589
CVE-2026-32589
PUBLISHED
CVSS 7.099999904632568 HIGH
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.
EPSS 0.24% · 15.2th percentile
Risk Scores
CVSS 3.1
7.099999904632568
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
EPSS Score
0.24%
15.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Quay 3 | |
| Red Hat | mirror registry for Red Hat OpenShift 2 | |
| Red Hat | mirror registry for Red Hat OpenShift | |
| Red Hat | Red Hat Quay 3 |
Timeline
- Apr 8, 2026 CVE Published
- Apr 9, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score