Description
A flaw was found in Red Hat Quay's custom build trigger handler. This vulnerability allows a user with organization repository administrative privileges and the FEATURE_BUILD_SUPPORT enabled to read arbitrary files on the build worker. This is possible due to insufficient validation of the build source configuration, which permits the use of a file:// Uniform Resource Identifier (URI) scheme. Exploiting this flaw can lead to unauthorized information disclosure.
Published: n/a
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

A flaw in Red Hat Quay’s custom build trigger handler, identified as a CWE-918 local file inclusion, allows an organization repository administrator with FEATURE_BUILD_SUPPORT enabled to read any file on the build worker by supplying a build source configuration that uses a file:// URI scheme. The insufficient validation of the build source configuration permits this local file inclusion, which can be used to exfiltrate confidential data from the build environment. The vulnerability requires legitimate administrative rights within the organization but still permits a malicious administrator to compromise information that should otherwise be protected.

Affected Systems

Red Hat Quay instances that enable custom build triggers. The affected product is the Quay custom build trigger handler; specific version numbers are not provided in the public data, so any deployment with this handler is potentially susceptible until a patch is applied.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity vulnerability. No EPSS score is available and the issue is not listed in CISA’s KEV catalog. The attack vector is likely local or within an organization, requiring repository administrative privileges. Because the flaw permits arbitrary file reads on the build worker, attackers with the necessary permissions could obtain sensitive configuration, credentials, or other secrets, leading to significant confidentiality impact.

Generated by OpenCVE AI on September 30, 2026 at 01:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Quay to the latest version that contains the fix for this local file inclusion vulnerability.
  • If custom build triggers are not needed, disable the FEATURE_BUILD_SUPPORT setting to eliminate the attack surface.
  • Restrict repository administrative privileges to trusted users and review build worker file access permissions to prevent unauthorized data exposure.

Generated by OpenCVE AI on September 30, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Red Hat Quay's custom build trigger handler. This vulnerability allows a user with organization repository administrative privileges and the FEATURE_BUILD_SUPPORT enabled to read arbitrary files on the build worker. This is possible due to insufficient validation of the build source configuration, which permits the use of a file:// Uniform Resource Identifier (URI) scheme. Exploiting this flaw can lead to unauthorized information disclosure.
Title quay: Local file inclusion via file:// scheme in Quay custom build trigger
Weaknesses CWE-918
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

threat_severity

Important


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-28T00:00:00Z

Links: CVE-2026-74246 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T02:00:15Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)