CVE-2026-11569 MEDIUM

CVE-2026-11569: Quay: quay: stored xss via filedrop svg upload

Vendor Red Hat
Product Red Hat Quay 3
Weakness CWE-79 · XSS
Published June 8, 2026
Last update June 8, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload a malicious SVG file containing JavaScript. The file is stored and served inline through the CDN, enabling stored cross-site scripting when a victim visits the archive URL.

Key dates

02Disclosure timeline

June 8, 2026 CVE published
June 8, 2026 Record updated