Skip to content
Red HatCVE-2026-74241

Red Hat Quay: attacker could inject LDAP filter metacharacters

Medium4.8CVE-2026-74241 · Published Aug 14, 2026 · updated Aug 20, 2026

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle attacks at the referral Directory Name (DN). This could also potentially influence which DN is used for password binding in multi-domain Active Directory environments.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat OpenShift Update Service
Product
all versionsNo fix yet
Red Hat Quay 3
Product
all versionsNo fix yet
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-90

More Red Hat advisories

All Red Hat
Advisory
Red Hat Quay: information disclosure
Medium5.3Aug 14
Red Hat Quay.: path traversal
Medium6.5Aug 14
Red Hat Quay: improper signature check
Medium5.9Aug 14
Red Hat Quay: information disclosure
Medium5.9Aug 14
Red Hat Quay: server-side request forgery
Medium4.2Aug 14
Red Hat Quay: improper authentication
Medium5.4Aug 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.