Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in Red Hat Quay's custom build trigger handler. The buildtrigger/customhandler.py module passes config.build_source as git_url with no SSRF or scheme validation. This accepts the file:// URI scheme, enabling local file read via git clone on the build worker. A user with FEATURE_BUILD_SUPPORT enabled and organization repository admin privileges can read arbitrary files accessible to the build worker process. This is a distinct code path from CVE-2026-16910 (webhook/Slack notification SSRF) and is not covered by the existing CVE.