---
id: CVE-2026-15927
title: |-
  A flaw was found in Red Hat Quay's repository-level mirror configuration
  feature
summary: |-
  A flaw was found in Red Hat Quay's repository-level mirror configuration
  feature. The POST and PUT handlers in endpoints/api/mirror.py accept an
  external_reference parameter without SSRF validation, unlike the
  organization-level mirror h…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: Red Hat
product: quay/quay-rhel8
affected:
  - quay/quay-rhel8 (all versions)
  - quay/quay-rhel8 (all versions)
  - quay/quay-rhel8 (all versions)
  - quay/quay-rhel8 (all versions)
  - quay/quay-rhel9 (all versions)
  - quay/quay-rhel9 (all versions)
  - quay/quay-rhel8 (all versions)
  - openshift/mirror-registry-rhel8 (all versions)
patched:
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.17
  - quay 3.9
published: '2026-07-21'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T18:17:10.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15927'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:50931'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:52968'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53520'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:54395'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:63307'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:69255'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70267'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-15927'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2501256'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15927.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-15927'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15927'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-21T13:12:11.259508Z'
epss: 0.00604
epssPercentile: 0.46754
ingestedAt: '2026-08-15T22:29:51.511Z'
---

## Overview

A flaw was found in Red Hat Quay's repository-level mirror configuration
feature. The POST and PUT handlers in endpoints/api/mirror.py accept an
external_reference parameter without SSRF validation, unlike the
organization-level mirror handlers which apply validate_external_registry_url().
A repository administrator can supply a crafted hostname that causes the Quay
mirror worker to make requests via Skopeo to internal network services, cloud
metadata endpoints, or other resources not intended to be reachable from the
Quay application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:53520** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53520)
- **RHSA-2026:52968** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52968)
- **RHSA-2026:63307** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63307)
- **RHSA-2026:54395** · Red Hat · fixed in: Red Hat Quay 3.17 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54395)
- **RHSA-2026:50931** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50931)
- **Red Hat VEX** · Important · affected: mirror registry for Red Hat OpenShift 2 · no fix planned: mirror registry for Red Hat OpenShift 2 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15927.json)
- **RHSA-2026:69255** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69255)
- **RHSA-2026:70267** · Red Hat · fixed in: Red Hat Quay 3.14 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70267)
