Description
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
Published: 2026-09-16
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution and credential exfiltration via GitHub Actions workflow
Action: Immediate Patch
AI Analysis

Impact

A flaw was discovered in the quay-builder-qemu component of Red Hat Quay 3. The release workflow calls a third‑party GitHub Action, Noelware/docker-manifest-action, pinned to the mutable @master branch. An attacker who can compromise that upstream action—by inserting malicious code into it or by controlling the branch—can cause the action to execute arbitrary commands during the build. This gives the attacker the ability to exfiltrate registry credentials, use the exposed default GitHub token, or publish malicious container images. The weakness is reflected by CWE‑1357, which involves insecure handling of external components.

Affected Systems

The vulnerability is present in Red Hat Quay 3, specifically when the quay-builder-qemu release workflow is used as shipped by Red Hat. All installations that rely on the default workflow with the Noelware/docker-manifest-action pinned to @master are affected; the affected product is Red Hat Quay 3. No specific patch version is provided in the CVE, so all current releases that use this workflow remain vulnerable until Red Hat publishes a fix.

Risk and Exploitability

The CVSS base score of 8 signals a high threat, but the EPSS score of less than 1 % suggests that exploitation is currently rare and no known exploits have been observed, and the vulnerability is not yet listed in the CISA KEV catalog. Even with the low current exploitation probability, the ability to inject code that runs under the build environment and to harvest sensitive credentials means that a successful attack could give an attacker full control of the container registry used by the organization. The attack likely requires a compromise of the upstream action repository or an invitation to contribute to it, but because the action is pinned to a mutable branch, any such compromise will automatically affect all future releases. No official workaround is available; an inbound update or configuration change is needed to prevent the attack.

Generated by OpenCVE AI on September 17, 2026 at 23:48 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Pin the Noelware/docker-manifest-action to a known‑good commit SHA rather than the mutable @master branch in the quay‑builder‑qemu workflow.
  • Rotate or revoke any default GitHub tokens and registry credentials that are accessible to the build workflow, and restrict write access to the action repository only to trusted users.
  • Upgrade or patch Red Hat Quay to a release that incorporates the latest fix for this issue; if a patch has not yet been released, consider disabling the release workflow until a resolution is available.

Generated by OpenCVE AI on September 17, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
Title Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope
First Time appeared Redhat
Redhat quay
Weaknesses CWE-1357
CPEs cpe:/a:redhat:quay:3
Vendors & Products Redhat
Redhat quay
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T18:22:29.443Z

Reserved: 2026-09-03T20:10:49.398Z

Link: CVE-2026-85469

cve-icon Vulnrichment

Updated: 2026-09-17T13:32:55.185Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:27.037

Modified: 2026-09-18T19:06:08.407

Link: CVE-2026-85469

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T20:43:38Z

Links: CVE-2026-85469 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:45:14Z

Weaknesses
  • CWE-1357

    Reliance on Insufficiently Trustworthy Component