---
id: CVE-2026-85469
title: A flaw was found in quay-builder-qemu
summary: >-
  A flaw was found in quay-builder-qemu. A remote attacker could exploit this by
  compromising the upstream `Noelware/docker-manifest-action` used in the
  release workflow, which is pinned to a mutable branch. This allows the
  attacker to inj…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-1357
vendor: Red Hat
product: quay/quay-builder-qemu-rhcos-rhel8
affected:
  - quay/quay-builder-qemu-rhcos-rhel8 (all versions)
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:06:08.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85469'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-85469'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2528219'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85469.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-85469'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85469'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00518
epssPercentile: 0.41572
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T13:32:50.037582Z'
ingestedAt: '2026-09-16T22:06:50.934Z'
---

## Overview

A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Quay 3 · no fix planned: Red Hat Quay 3 · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85469.json)
