AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-74247

MEDIUM · CVSS 4.2 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A Server-Side Request Forgery (SSRF) vulnerability exists in Red Hat Quay, allowing users with FEATURE_BUILD_SUPPORT enabled and repository write access to exploit the build API. This flaw enables the submission of malicious URLs, potentially exposing sensitive internal information by allowing the Quay builder to make unauthorized requests to internal network addresses. Organizations using Red Hat Quay should prioritize addressing this vulnerability to mitigate risks associated with internal data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-74247
Severity
MEDIUM
CVSS
4.2
EPSS
N/A

Original NVD Description

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.