Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85469— Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope

Quick assessment

Affected
Red Hat Red Hat Quay 3
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

中发现了一个缺陷。远程攻击者可通过利用发布工作流中使用的上游 的漏洞来利用该缺陷,该 Action 被固定到一个可变分支上。这使得攻击者能够注入任意代码,从而导致敏感的注册表凭据泄露或恶意镜像被发布。此外,该工作流还暴露了默认的 GitHub Token,从而加剧了被攻破后的影响严重程度。

CVSS 8.0 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85469

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1357
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Quay 3 - cpe:/a:redhat:quay:3

II. Public POCs for CVE-2026-85469

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85469

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85469 (1)

Other References for CVE-2026-85469 (1)

Same Patch Batch · Red Hat · 2026-09-16 · 10 CVEs total

CVE-2026-74909 8.1 HIGH Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enfo
CVE-2026-79651 7.5 HIGH Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching
CVE-2026-18212 7.5 HIGH Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state
CVE-2026-42784 7.4 HIGH Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusio
CVE-2026-17526 7.2 HIGH Keycloak-services: keycloak-services: privilege escalation via impersonation role allows t
CVE-2026-92615 6.6 MEDIUM Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tena
CVE-2026-92358 6.4 MEDIUM Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil
CVE-2026-92091 5.9 MEDIUM Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops
CVE-2026-19607 5.3 MEDIUM Keycloak-services: keycloak-services: broker-originated username collision causes account

IV. Related Vulnerabilities

V. Comments for CVE-2026-85469

No comments yet


Leave a comment