CVE-2026-56097: Rubygem-katello: sql injection in registry proxy via labels

Published Jun 18, 2026
·
Updated

A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods checkblobpushorglabel and getmatchingproductsfromorg take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the createpersonalaccesstokens permission, even if the user access is restricted, with no Organization or Location assigned.

Other sources

Description

An authenticated SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController.

Specifically, the methods checkblobpushorglabel and getmatchingproductsfromorg take user-supplied labels directly from the request path and interpolate them into raw SQL fragments.

Crucially, this vulnerability is accessible to a user possessing only the createpersonalaccesstokens permission (See F-36 Improper Authorization logic allows Resource Enumeration and F-37 Improper RBAC Mapping and Missing Filters Enable Unauthorized Controller Access). Even if the user access is restricted, with no Organization or Location assigned.

Affected Code in app/controllers/katello/api/registry/registryproxiescontroller.rb:

--------------------------------------------------------------------------------

Organization lookup

org = Organization.where("LOWER(label) = '#{orglabel}'") # convert to lowercase

Product lookup

return organization.products.where("LOWER(label) = '#{productlabel}'") # convert to lowercase

--------------------------------------------------------------------------------

Impact

Global Data Exfiltration: Low privileged users can bypass all logical data separation and multi-tenancy restrictions to dump the entire PostgreSQL database, including sensitive tables such as users and settings.

Vertical Privilege Escalation: By exfiltrating the users table, password hashes for administrative accounts (e.g., admin) can be recovered and cracked offline. No cleartext credentials were found, other sensitive credentials such as PATs and sessionid are also hashed.

The Ruby pg driver used by ActiveRecord does not support stacked queries. This prevents the execution of direct DML/DDL statements (e.g., UPDATE, INSERT, DROP) through this specific injection vector. Therefore, the injection context is limited to SELECT statement fragments.

Recommendations

Implement Parameterized Queries: Modify RegistryProxiesController to use ActiveRecord's parameterized query syntax.

Proposed Fixes:

--------------------------------------------------------------------------------

org = Organization.where("LOWER(label) = ?", orglabel.downcase)

return organization.products.where("LOWER(label) = ?", productlabel.downcase)

--------------------------------------------------------------------------------

Apply Authorization Controls: Enforce a check to ensure the user has permissions for the specific Organization/Product before performing the database lookup.

— Red Hat

Affected Software

1 affected component
rubygems/katello<4.21.2, <5.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rubygem-katello to a version that resolves this vulnerability.

    Fixed in 4.21.2
  2. Upgrade

    Upgrade rubygem-katello to a version that resolves this vulnerability.

    Fixed in 5.0.1
  3. Compensating control

    In RegistryProxiesController, enforce a permission check confirming the user is authorized for the specific Organization and Product before performing the database lookup.

  4. Compensating control

    Modify check_blob_push_org_label and get_matching_products_from_org to use ActiveRecord parameterized queries instead of interpolating user-supplied labels into raw SQL; use predicates such as LOWER(label) = ? with the downcased label.

Event History

Jun 18, 2026
Data Sourced
via Red Hat·07:00 PM
DescriptionSeverityAffected Software
Oct 1, 2026
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203