CVE-2026-2377 Details
Description
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery (SSRF), could allow an attacker to send requests from the application's internal network, potentially leading to the disclosure of sensitive information.
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Red Hat Quay versions 3 (both RHEL 8 and RHEL 9) and in the OpenShift Mirror Registry component 'openshift/mirror-registry-rhel8'. This vulnerability allows authenticated users to exploit the log export feature by providing a specially crafted URL. The application's backend then makes arbitrary requests to internal network resources, potentially leading to unauthorized access to sensitive information or other internal systems.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | redhat-SADP |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat mirror registry for red hat openshift | 2.0 |
CPE
Remediation
| |
| redhat quay | 3.0.0 |
CPE
Remediation
| |
Change History
25 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | redhat-SADP |
| Sep 9, 2026 | CVE Modified | redhat-SADP |
| Sep 9, 2026 | CVE Modified | [email protected] |
| Aug 17, 2026 | CVE Modified | redhat-SADP |
| Aug 15, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | redhat-SADP |
| Aug 11, 2026 | CVE Modified | [email protected] |
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jul 20, 2026 | CVE Modified | redhat-SADP |
| Jul 18, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 1, 2026 | CVE Modified | redhat-SADP |
| Jul 1, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 9, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 8, 2026 | New CVE Received | [email protected] |