Bug 2439201 (CVE-2026-2377) - CVE-2026-2377 mirror-registry: quay: quay: Server-Side Request Forgery via log export functionality
Summary: CVE-2026-2377 mirror-registry: quay: quay: Server-Side Request Forgery via lo...
Keywords:
Status: NEW
Alias: CVE-2026-2377
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-11 22:13 UTC by OSIDB Bzimport
Modified: 2026-04-08 16:21 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-02-11 22:13:00 UTC
The log export functionality allows authenticated users to supply an arbitrary callback_url, which is later processed asynchronously by a backend worker. The backend performs server-side HTTP requests to this URL, follows redirects, and preserves HTTP methods and request bodies. This enables arbitrary outbound requests originating from within the application’s internal network context.


Note You need to log in before you can comment on or make changes to this bug.