theinfosecnews

CVE-2026-32589

Published April 8, 2026 · Updated April 9, 2026

7.1CVSS
high

What This Means

CVE-2026-32589 is a high-severity vulnerability in Red Hat Quay that allows an authenticated user with push access to interfere with ongoing image uploads by other users, including those outside their own repositories. An attacker could potentially read, modify, or cancel uploads, compromising the integrity of container images. Security teams should apply the latest patches from Red Hat for Quay to mitigate this risk and ensure that access controls are strictly enforced.

Official Description+

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.

Recommended Actions

  1. Check if your systems use any of the affected products listed above.
  2. Apply vendor patches immediately if available.
  3. Monitor vendor advisories for updates and additional mitigations.
  4. Review logs for indicators of compromise related to CVE-2026-32589.

Related Coverage