CVE-2026-10052

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network reconnaissance from the Quay pod's network position, potentially mapping the internal network infrastructure.
Configurations

No configuration.

History

29 May 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 09:16

Updated : 2026-05-29 14:06


NVD link : CVE-2026-10052

Mitre link : CVE-2026-10052

CVE.ORG link : CVE-2026-10052


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)