CVE-2026-2376

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:redhat:mirror_registry:-:*:*:*:*:openshift:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

02 Jun 2026, 19:23

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:mirror_registry:-:*:*:*:*:openshift:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
First Time Redhat
Redhat mirror Registry
Redhat enterprise Linux
Redhat quay
Summary
  • (es) Se encontró una vulnerabilidad en mirror-registry donde un usuario autenticado puede engañar al sistema para que acceda a sistemas internos o restringidos no previstos al proporcionar direcciones web maliciosas. Cuando la aplicación procesa estas direcciones, sigue automáticamente las redirecciones sin verificar el destino final, lo que permite a los atacantes enrutar solicitudes a sistemas a los que no deberían tener acceso.
References () https://access.redhat.com/security/cve/CVE-2026-2376 - () https://access.redhat.com/security/cve/CVE-2026-2376 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2439117 - () https://bugzilla.redhat.com/show_bug.cgi?id=2439117 - Vendor Advisory
References () https://github.com/quay/quay/pull/5074 - () https://github.com/quay/quay/pull/5074 - Issue Tracking, Patch

12 Mar 2026, 21:16

Type Values Removed Values Added
References
  • () https://github.com/quay/quay/pull/5074 -

12 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 19:16

Updated : 2026-06-02 19:23


NVD link : CVE-2026-2376

Mitre link : CVE-2026-2376

CVE.ORG link : CVE-2026-2376


JSON object : View

Products Affected

redhat

  • mirror_registry
  • enterprise_linux
  • quay
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')