REDHAT-BUG-2486194: CSRF

Published Jun 8, 2026
·
Updated

The filedrop endpoint (POST /api/v1/filedrop/) accepts any mimeType without validation, including image/svg+xml, text/html, and application/javascript. An attacker with repository write access can upload a malicious SVG file containing JavaScript, create a build referencing the fileid, and obtain an archiveurl that serves the SVG through the CDN. When a victim visits the archive URL, the browser renders the SVG inline and executes the embedded JavaScript. The malicious SVG is stored in the object storage backend and served through a legitimate Quay domain. However, session hijacking is not possible as the csrftoken session cookie is configured with HttpOnly and Secure attributes.

Affected Software

1 affected component
Red Hat Quay

Event History

Jun 8, 2026
Data Sourced
via Red Hat·09:17 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2486194?

The severity of REDHAT-BUG-2486194 is medium, rated at 4.

2

How does the vulnerability REDHAT-BUG-2486194 allow exploitation?

REDHAT-BUG-2486194 allows exploitation through the filedrop endpoint accepting any mimeType, enabling malicious SVG files to be uploaded.

3

Who can exploit REDHAT-BUG-2486194?

An attacker with repository write access can exploit REDHAT-BUG-2486194.

4

What is the potential impact of REDHAT-BUG-2486194?

The potential impact of REDHAT-BUG-2486194 includes the ability to execute JavaScript contained in uploaded SVG files once referenced in a build.

5

What action should be taken to mitigate REDHAT-BUG-2486194?

To mitigate REDHAT-BUG-2486194, validation of mimeTypes at the filedrop endpoint needs to be implemented to restrict uploads to safe file types.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203