PT-2026-94091 · Noelware+1 · Docker-Manifest-Action+1

CVE-2026-85469

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions quay-builder-qemu (affected versions not specified)
Description A flaw exists where the release workflow uses the upstream Noelware/docker-manifest-action pinned to a mutable branch. A remote attacker could compromise this upstream action to inject arbitrary code into the workflow. Since the action executes after registry authentication, this could lead to the exfiltration of sensitive registry credentials or the publication of malicious images. Additionally, the workflow exposes the default GitHub token, which increases the potential impact of the compromise.
Recommendations Replace third-party Actions referenced by branches or movable tags with full commit hashes. Implement explicit GitHub Actions permissions: blocks to restrict job capabilities to only what is required. Review registry push history, image digests, and release timestamps for unauthorized changes. Restrict the use of the Noelware/docker-manifest-action until it is pinned to a specific commit hash.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85469

Affected Products

Docker-Manifest-Action
Quay-Builder-Qemu