CVE-2026-15927
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-918
Falsificación de solicitud en servidor (SSRF)
Fecha de publicación:
21/07/2026
Última modificación:
21/07/2026
Descripción
*** Pendiente de traducción *** A flaw was found in Red Hat Quay&#39;s repository-level mirror configuration<br />
feature. The POST and PUT handlers in endpoints/api/mirror.py accept an<br />
external_reference parameter without SSRF validation, unlike the<br />
organization-level mirror handlers which apply validate_external_registry_url().<br />
A repository administrator can supply a crafted hostname that causes the Quay<br />
mirror worker to make requests via Skopeo to internal network services, cloud<br />
metadata endpoints, or other resources not intended to be reachable from the<br />
Quay application.
Impacto
Puntuación base 3.x
6.80
Gravedad 3.x
MEDIA



