PT-2026-72129 · Red Hat · Red Hat Quay

CVE-2026-74243

·

Published

2026-08-14

·

Updated

2026-08-18

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Red Hat Quay (affected versions not specified)
Description A flaw exists when the SECURITY SCANNER V4 PSK (pre-shared key) is not configured. A remote unauthenticated attacker can send POST requests to the security scanner notification endpoint, enabling them to flood the notification queue and inject path traversal characters into Clair API URL paths. This can result in worker resource exhaustion and blind path manipulation on the configured Clair host, potentially leading to a denial of service.
Recommendations Set the SECURITY SCANNER V4 PSK pre-shared key to secure the security scanner notification endpoint.

Fix

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74243

Affected Products

Red Hat Quay