CVE-2026-105447Medium· 5.5▾ SunlitA flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with rea…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to retrieve these delegate tokens. This issue allows a restricted user to bypass read-only limitations and push arbitrary container images to private repositories, leading to privilege escalation.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-18255High· 7.2A flaw was found in Quay
CVE-2026-95811Medium· 6.5Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost…
CVE-2026-96512High· 7.8A flaw was found in sudo
CVE-2026-15927Medium· 6.8A flaw was found in Red Hat Quay's repository-level mirror configuration feature
CVE-2026-71297Medium· 5.4A flaw was found in the maestro gRPC broker
CVE-2026-71299Medium· 6.5A flaw was found in Maestro