CVE-2026-16910 MEDIUM

CVE-2026-16910: Quay: ssrf in red hat quay notification webhooks (slack/generic)

Vendor Red Hat
Product Red Hat OpenShift Update Service
Weakness CWE-918 · SSRF
Published July 24, 2026
Last update July 24, 2026

CVSS base score

5.5/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application.

Key dates

02Disclosure timeline

July 24, 2026 CVE published

Related vulnerabilities

04Related CVE