← All Advisories

Unsafe Deserialization in Red Hat Quay Resumable Upload Handling

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-32590

Key Details

CVECVE-2026-32590
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Mirror Registry for Red Hat OpenShift and Red Hat Quay
Classified asCWE-502 (Deserialization of Untrusted Data)
Exploitation prediction (EPSS)0.79% probability of exploitation in the next 30 days (54% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatMirror Registry for Red Hat OpenShift
Red HatQuay
SubsystemsCore Infrastructure
SectorsMultiple

What to Know

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-32590
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-32590
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-32590