boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-32591MEDIUM
Red Hat Red Hat Quay 3.1 — Mirror-registry: quay: server-side request forgery in proxy cache upstream registry configuration
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  L  N    5.5   .0032   25.4     —
AFFECTED
  Product                                  Versions     Fixed
  Red Hat Quay 3.1                         unspecified  1783750447
  Red Hat Quay 3.12                        unspecified  1783751865
  Red Hat Quay 3.12                        unspecified  1784353904
  Red Hat Quay 3.15                        unspecified  1784351966
  Red Hat Quay 3.16                        unspecified  1783955846
  Red Hat Quay 3.17                        unspecified  1780604033
  Red Hat Quay 3.18                        unspecified  1784987273
  Red Hat Quay 3.9                         unspecified  1784125838
  mirror registry for Red Hat OpenShift    unspecified  —
  mirror registry for Red Hat OpenShift 2  unspecified  —
TIMELINE
  Mar 12  Reserved by redhat
  Apr 8   Published (CNA: redhat)
  Aug 17  RESCORED — CVE-2026-32591 (Red Hat Quay 3.1). CVSS 5.2 → 5.5 (NVD).
CWE-918 · CNA: redhat · CVSS v3.1 · 11 references · NVD status: Modified

Description

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization administrator privileges could supply a crafted hostname to force the Quay server to make requests to internal network services, cloud infrastructure endpoints, or other resources that should not be accessible from the Quay application.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 12, 2026ReservedReserved by redhat
April 8, 2026PublishedPublished (CNA: redhat)
August 17, 2026RESCOREDRESCORED — CVE-2026-32591 (Red Hat Quay 3.1). CVSS 5.2 → 5.5 (NVD).

Affected

Affected products and packages — 10 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red HatRed Hat Quay 3.11783750447
Red HatRed Hat Quay 3.121783751865
Red HatRed Hat Quay 3.121784353904
Red HatRed Hat Quay 3.151784351966
Red HatRed Hat Quay 3.161783955846
Red HatRed Hat Quay 3.171780604033
Red HatRed Hat Quay 3.181784987273
Red HatRed Hat Quay 3.91784125838
Red Hatmirror registry for Red Hat OpenShift
Red Hatmirror registry for Red Hat OpenShift 2

Weaknesses

CWE-918

References (11)

Related

Authoritative record: CVE-2026-32591 at cve.org

Vendors: red hat

Weaknesses: CWE-918

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-32591 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.