boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-32590HIGH
Red Hat mirror registry for Red Hat OpenShift 2.0 — Mirror-registry: remote code execution using pickle deserialization
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0041   34.6     —
AFFECTED
  Product                                    Versions     Fixed
  mirror registry for Red Hat OpenShift 2.0  unspecified  1782177012
  Red Hat Quay 3.1                           unspecified  1779822261
  Red Hat Quay 3.12                          unspecified  1779811412
  Red Hat Quay 3.14                          unspecified  1779689392
  Red Hat Quay 3.15                          unspecified  1780891395
  Red Hat Quay 3.16                          unspecified  1779204086
  Red Hat Quay 3.17                          unspecified  1779922205
  Red Hat Quay 3.17                          unspecified  1780604033
  Red Hat Quay 3.18                          unspecified  1784987273
  Red Hat Quay 3.9                           unspecified  1779811473
  + 1 more
TIMELINE
  Mar 12  Reserved by redhat
  Apr 8   Published (CNA: redhat)
  Aug 15  RESCORED — CVE-2026-32590 (Red Hat mirror registry for Red Hat OpenShift 2.0). CVSS 7.1 → 8.8 (NVD).
CWE-502 · CNA: redhat · CVSS v3.1 · 12 references · NVD status: Modified

Description

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 12, 2026ReservedReserved by redhat
April 8, 2026PublishedPublished (CNA: redhat)
August 15, 2026RESCOREDRESCORED — CVE-2026-32590 (Red Hat mirror registry for Red Hat OpenShift 2.0). CVSS 7.1 → 8.8 (NVD).

Affected

Affected products and packages — 11 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red Hatmirror registry for Red Hat OpenShift 2.01782177012
Red HatRed Hat Quay 3.11779822261
Red HatRed Hat Quay 3.121779811412
Red HatRed Hat Quay 3.141779689392
Red HatRed Hat Quay 3.151780891395
Red HatRed Hat Quay 3.161779204086
Red HatRed Hat Quay 3.171779922205
Red HatRed Hat Quay 3.171780604033
Red HatRed Hat Quay 3.181784987273
Red HatRed Hat Quay 3.91779811473
Red Hatmirror registry for Red Hat OpenShift

Weaknesses

CWE-502

References (12)

Related

Authoritative record: CVE-2026-32590 at cve.org

Vendors: red hat

Weaknesses: CWE-502

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-32590 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.