Description

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.

INFO

Published Date :

2026-03-12T19:11:16.569Z

Last Modified :

2026-03-12T20:46:18.921Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-2376 vulnerability.

Vendors Products
Mirror-registry
  • Quay
Redhat
  • Mirror Registry
  • Quay

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact