CVE-2026-56098: Rubygem-katello: improper authorization logic allows resource enumeration
A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registryauthorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.
Other sources
Description
The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registryauthorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement).
This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.
--------------------------------------------------------------------------------
$ cat /usr/share/gems/gems/katello-4.20.0.rc1/app/controllers/katello/api/registry/registryproxiescontroller.rb
def registryauthorize
@repository = findreadablerepository
return true if ['GET', 'HEAD'].include?(request.method) && @repository && !requireuserauthorization?
return true if authenticatefromrequest(request.headers['Authorization'])
unauthorized [should be: “unauthorized and return”]
end
def unauthorized
redirectauthorizationheaders
rendererror('unauthorized', :status => :unauthorized)
false [no return here neither]
end
--------------------------------------------------------------------------------
Impact
User Enumeration: Attackers can verify the existence of usernames. Invalid users cause a server-side crash (500 Internal Server Error) because the fall-through logic cannot handle a null user object. Valid users trigger a semantic error (404 NAMEUNKNOWN), confirming their presence.
Resource Mapping: Unauthorized users can map hidden organizational structures. By observing the discrepancy between "Organization not found" and "Product not found", an attacker can confirm the existence of Organizations and Products they are explicitly forbidden from viewing.
Exploit Chain Enabler: This vulnerability provides the necessary "transport" for the F-38 SQL Injection in Registry Proxy via labels, allowing malicious payloads to reach the database layer despite failing initial authorization checks.
RECOMMENDATIONS
Fix Control Flow: Add an explicit “and return” to the unauthorized method call within registryauthorize to ensure the filter chain terminates immediately and prevents execution fall-through.
Normalize Error Responses: Configure the Registry API to return a uniform 401 Unauthorized response for all failed authorization attempts to eliminate the enumeration oracle.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygem-katelloto a version that resolves this vulnerability.Fixed in 4.21.2 - Upgrade
Upgrade
rubygem-katelloto a version that resolves this vulnerability.Fixed in 5.0.1 - Configuration
Configure the Registry API to return a uniform 401 Unauthorized response for all failed authorization attempts.
Katello Registry API failed authorization response = 401 Unauthorized
Event History
Frequently Asked Questions
Who can exploit this issue?
An unprivileged attacker with low-level privileges can exploit it remotely. No user interaction is required.
What information can be exposed?
Differential responses can allow enumeration of valid Users, Organizations, and Products across the entire instance. The provided impact data indicates low confidentiality impact, with no integrity or availability impact.
What is required for exploitation?
The vulnerable authorization path must be reachable in Katello's RegistryProxiesController. Exploitation relies on the authorization filter continuing execution after it identifies an unauthorized request, and is rated low complexity.
Are fixes or advisories available?
The provided references list Red Hat advisories RHSA-2026:74503, RHSA-2026:74504, and RHSA-2026:74506. The supplied data does not identify the affected or fixed package versions.