VDB
CVE-2026-32590
CVE-2026-32590
PUBLISHED
CVSS 7.099999904632568 HIGH
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.
EPSS 0.14% · 33.3th percentile
Risk Scores
CVSS v3.1
7.099999904632568
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.14%
33.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | mirror registry for Red Hat OpenShift | |
| Red Hat | Red Hat Quay 3 | |
| Red Hat | mirror registry for Red Hat OpenShift 2 | |
| Red Hat | Red Hat Quay 3 |
Timeline
- Apr 8, 2026 CVE Published
- Apr 9, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 21, 2026 Distribution Patch
- May 21, 2026 Security Advisory
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score