CVE-2026-32590 Details
Description
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.
A remote code execution vulnerability exists in Red Hat Quay version 3.12.x, arising from the insecure handling of resumable container image layer uploads. The application uses Python's pickle module to serialize and deserialize hash state objects, which are then stored in the database. This process can be manipulated to execute arbitrary code on the Quay server. Exploitation requires valid login credentials, either through the web interface or via a container tool like Podman.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat mirror registry for red hat openshift | 2.0 |
CPE
Remediation
| |
| redhat quay | 3.0.0 |
CPE
Remediation
| |
Change History
20 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | [email protected] |
| Aug 15, 2026 | CVE Modified | [email protected] |
| Aug 11, 2026 | CVE Modified | [email protected] |
| Jul 29, 2026 | CVE Modified | [email protected] |
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jul 19, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | [email protected] |
| Jun 23, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 9, 2026 | CVE Modified | [email protected] |
| Jun 9, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 8, 2026 | New CVE Received | [email protected] |