quay/quay-rhel9 vulnerabilities
CVEs whose affected-version data names the quay/quay-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-18255High· 7.2A flaw was found in Quay
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot …
▾ TwilightRed Hat · quay/quay-rhel8EPSS 0.65%via NVD
CVE-2026-15927Medium· 6.8A flaw was found in Red Hat Quay's repository-level mirror configuration feature
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror h…
▾ SunlitRed Hat · quay/quay-rhel8EPSS 0.60%via NVD