CVE-2026-102295
Received Received - Intake

Reflected XSS in Quay Container Registry

Vulnerability report for CVE-2026-102295, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: redhat-SADP

Description

A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaScript code within a user's browser session. By tricking a logged-in user into visiting a specially crafted link, an attacker can exploit improper input sanitization to run client-side scripts in the application context. Successful exploitation could allow the attacker to compromise the user's session, access sensitive registry information, or perform unauthorized actions on their behalf.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
red_hat quay 3.16
quay quay *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a DOM-based cross-site scripting (XSS) vulnerability in Red Hat Quay's OAuth callback handler. It allows a remote attacker to execute arbitrary JavaScript in a user's browser by tricking them into clicking a specially crafted link. The flaw occurs due to improper input sanitization when the format=json parameter is used, enabling malicious code execution within the Quay registry's origin.

Detection Guidance

To detect this XSS vulnerability in Quay, monitor network traffic for suspicious OAuth callback requests containing the format=json parameter. Check browser logs or proxy logs for URLs with malicious JavaScript payloads in the fragment or access_token values. Inspect Quay server logs for unusual activity during OAuth flows.

Impact Analysis

An attacker could compromise your Quay session, access sensitive registry data, or perform unauthorized actions on your behalf. This requires you to click a malicious link while logged into Quay. The attack bypasses OAuth state validation and does not need authentication to exploit.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. Compromised user sessions may expose regulated data, requiring breach notifications and compliance investigations.

Mitigation Strategies

Immediate mitigation steps include disabling the affected OAuth local callback handler if possible, implementing strict input validation for the format=json parameter, and updating Quay to a patched version if available. Since Red Hat states mitigation options are unavailable, consider restricting access to the OAuth callback endpoint or using a web application firewall to block malicious payloads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102295. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart