PT-2026-72129 · Red Hat · Red Hat Quay
CVE-2026-74243
·
Published
2026-08-14
·
Updated
2026-08-18
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat Quay (affected versions not specified)
Description
A flaw exists when the
SECURITY SCANNER V4 PSK (pre-shared key) is not configured. A remote unauthenticated attacker can send POST requests to the security scanner notification endpoint, enabling them to flood the notification queue and inject path traversal characters into Clair API URL paths. This can result in worker resource exhaustion and blind path manipulation on the configured Clair host, potentially leading to a denial of service.Recommendations
Set the
SECURITY SCANNER V4 PSK pre-shared key to secure the security scanner notification endpoint.Fix
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Quay