REDHAT-BUG-2545916: Medium severity Red Hat Quay vulnerability

Published Oct 5, 2026
·
Updated

A flaw was found in Quay's build trigger API endpoints. The BuildTriggerList.get and BuildTrigger.get handlers in endpoints/api/trigger.py hardcode canadmin=True when serializing trigger data via the triggerview function, regardless of whether the caller is a full administrator or a global read-only superuser. This causes the trigger configuration, including delegate write tokens embedded in webhook endpoint URLs, to be exposed to users in the GLOBALREADONLYSUPERUSERS list. These delegate tokens carry push scope for the repository and can be used to push arbitrary container images to private repositories, bypassing the read-only restriction of the caller's role.

Affected Software

1 affected component
Red Hat Quay

Event History

Oct 5, 2026
Data Sourced
via Red Hat·01:56 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which users can access the exposed trigger configuration?

Users listed in GLOBAL_READONLY_SUPER_USERS can receive trigger configuration data even though they are intended to have read-only global access.

2

What does an attacker need to exploit this issue?

An attacker needs access as a global read-only superuser and access to the affected build trigger API endpoints. The exposed webhook URLs include delegate write tokens.

3

What can be done with an exposed delegate token?

The token has push scope for the associated repository and can be used to push arbitrary container images to private repositories. This bypasses the read-only restriction of the user who obtained it.

4

How can administrators determine whether they may be exposed?

Review whether any users are configured in GLOBAL_READONLY_SUPER_USERS and whether build triggers are configured for private repositories. Those users may be able to retrieve trigger configuration containing repository write tokens.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203