Description
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.
Problem types
URL Redirection to Untrusted Site ('Open Redirect')
Product status
Timeline
| 2026-02-11: | Reported to Red Hat. |
| 2026-03-03: | Made public. |
Credits
Red Hat would like to thank Antony Di Scala, Luffy Zhang, and Michael Whale for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-2376
bugzilla.redhat.com/show_bug.cgi?id=2439117 (RHBZ#2439117)
github.com/quay/quay/pull/5074