PT-2026-94091 · Noelware+1 · Docker-Manifest-Action+1
CVE-2026-85469
·
Published
2026-09-16
·
Updated
2026-09-19
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
quay-builder-qemu (affected versions not specified)
Description
A flaw exists where the release workflow uses the upstream
Noelware/docker-manifest-action pinned to a mutable branch. A remote attacker could compromise this upstream action to inject arbitrary code into the workflow. Since the action executes after registry authentication, this could lead to the exfiltration of sensitive registry credentials or the publication of malicious images. Additionally, the workflow exposes the default GitHub token, which increases the potential impact of the compromise.Recommendations
Replace third-party Actions referenced by branches or movable tags with full commit hashes.
Implement explicit GitHub Actions
permissions: blocks to restrict job capabilities to only what is required.
Review registry push history, image digests, and release timestamps for unauthorized changes.
Restrict the use of the Noelware/docker-manifest-action until it is pinned to a specific commit hash.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker-Manifest-Action
Quay-Builder-Qemu