CyberRota
← Ana sayfaya dön

CVE-2026-16910

MEDIUM · CVSS 5.5 EPSS %0.21

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-24T08:16:26.790 · Çekilme zamanı: 2026-07-25T06:06:29.144613+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-16910
Severity
MEDIUM
CVSS
5.5
EPSS
%0.21

Orijinal NVD Açıklaması

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application.