Description
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.
Problem types
Deserialization of Untrusted Data
Product status
Timeline
| 2026-03-12: | Reported to Red Hat. |
| 2026-04-08: | Made public. |
Credits
Red Hat would like to thank Antony Di Scala and Michael Whale for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-32590
bugzilla.redhat.com/show_bug.cgi?id=2446964 (RHBZ#2446964)