CVE-2026-32590 is a vulnerability in Red Hat Quay's resumable container image layer upload functionality that allows attackers to execute arbitrary code on affected servers through tampering with intermediate upload data stored in the database. The flaw affects Red Hat Quay and requires authentication to exploit, making it a privilege escalation risk for authenticated users with upload capabilities. The vulnerability carries a CVSS score of 8.8 (High) with network accessibility and low attack complexity, indicating that remote exploitation is straightforward once authenticated. The attack provides complete compromise of confidentiality, integrity, and availability on the affected Quay server. The EPSS score of 0.00081 suggests this vulnerability poses a lower relative risk compared to the broader CVE landscape. There is currently no evidence of active exploitation in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog and its inactive status on threat tracking lists. The FAUCET Risk Score of 42.0 reflects moderate concern, though the low EPSS score and lack of public exploit code suggest limited immediate threat. Organizations running Red Hat Quay should prioritize patching based on environmental risk rather than imminent threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE match | cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.