CVE-2026-74241: Quay: ldap referral filter injection in quay external ldap authentication

Published Aug 14, 2026
·
Updated

A flaw was found in Red Hat Quay's external LDAP authentication handling. When an LDAP referral is returned during authentication, the referral handler at data/users/externalldap.py:700 constructs a search filter using the raw usernameoremail input without applying escapefilterchars(), unlike the normal authentication path which correctly escapes the input. This allows LDAP filter metacharacters (, (, )) in the username to be injected into the referral path's search filter. While SCOPEBASE limits the search to a single DN (preventing directory enumeration) and a separate simplebinds password check prevents direct authentication bypass, an attacker could use this to perform user-existence oracle attacks at the referral DN and potentially influence which DN enters the password bind in multi-domain Active Directory environments.

Other sources

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle attacks at the referral Directory Name (DN). This could also potentially influence which DN is used for password binding in multi-domain Active Directory environments.

MITRE

Affected Software

1 affected component
Red Hat Quay

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Mitigate LDAP referral filter injection by preventing LDAP referrals from being followed during Quay external LDAP authentication, so that the referral handler does not construct the referral search filter from the raw username_or_email input at data/users/externalldap.py:700.

Event History

Aug 14, 2026
Data Sourced
via Red Hat·07:50 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·10:43 PM
Data Sourced
via MITRE·10:43 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-74241?

CVE-2026-74241 has a medium severity rating of 4.8.

2

How does CVE-2026-74241 affect Red Hat Quay?

CVE-2026-74241 allows for LDAP referral filter injection in the external LDAP authentication process.

3

How do I fix CVE-2026-74241?

To mitigate CVE-2026-74241, ensure that Red Hat Quay is updated to a version that includes the fix for the LDAP referral handling issue.

4

What software is affected by CVE-2026-74241?

The vulnerability CVE-2026-74241 affects Red Hat Quay.

5

Where can I find more information about CVE-2026-74241?

For detailed information on CVE-2026-74241, refer to documentation and announcements from Red Hat.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203