Red HatCVE-2026-15927
mirror registry for Red Hat OpenShift 2: server-side request forgery
Medium6.8CVE-2026-15927 · Published Jul 21, 2026 · updated Sep 22, 2026
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror handlers which apply validate_external_registry_url(). A repository administrator can supply a crafted hostname that causes the Quay mirror worker to make requests via Skopeo to internal network services, cloud metadata endpoints, or other resources not intended to be reachable from the Quay application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mirror registry for Red Hat OpenShift 2 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
- www.cve.org/CVERecord?id=CVE-2026-15927
- nvd.nist.gov/vuln/detail/CVE-2026-15927
- access.redhat.com/errata/RHSA-2026:50931
- access.redhat.com/errata/RHSA-2026:52968
- access.redhat.com/errata/RHSA-2026:53520
- access.redhat.com/errata/RHSA-2026:54395
- access.redhat.com/errata/RHSA-2026:63307
- access.redhat.com/errata/RHSA-2026:69255
- access.redhat.com/errata/RHSA-2026:70267
- access.redhat.com/security/cve/CVE-2026-15927
- bugzilla.redhat.com/show_bug.cgi?id=2501256
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 21 | Red Hat libarchive: integer overflow | Low2.9 | No fix yet |
| Jul 21 | Red Hat Enterprise Linux 10: information disclosure | Low3.4 | No fix yet |
| Jul 21 | Red Hat Enterprise Linux 10: out-of-bounds read | Medium4.2 | No fix yet |
| Jul 21 | Red Hat ansible-core: argument injection | High7.8 | No fix yet |
| Jul 21 | Red Hat libssh. Logic errors: denial of service | Low3.1 | No fix yet |
| Jul 21 | Red Hat libssh: use after free | Medium4.3 | No fix yet |