Sceawere

Vulnerability Detail

CVE-2026-102576UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Quay Open Redirect XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
3h ago
Vendor
Red Hat
Product
Red Hat Quay 3
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in Quay. A remote attacker could trick a user into logging in through a crafted link, resulting in cross-site scripting (XSS). Because the application does not validate the redirect destination before navigating, this flaw allows the execution of arbitrary script in the context of the victim's authenticated browser session. Successful exploitation requires the target Quay deployment to use direct database authentication and the victim to complete login through the malicious URL.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-10-05T18:17:31.200Z",
  "pubdate": "2026-10-05T18:17:31.200Z",
  "executiveSummary": "A cross-site scripting (XSS) vulnerability exists in Quay due to improper validation of redirect parameters during the authentication process.\nThe vulnerability occurs because the application fails to sanitize or validate the destination URL provided during login, allowing an attacker to inject arbitrary scripts.\nAffected systems include Quay deployments configured to use direct database authentication.\nAn attacker can exploit this flaw by crafting a malicious link that forces a victim to navigate to an attacker-controlled script within their authenticated browser session.\nThis vulnerability poses a significant risk, as successful exploitation enables the execution of malicious code in the context of the user's active session, potentially leading to session hijacking, data theft, or unauthorized actions performed on behalf of the authenticated user.\nExploitation requires the victim to interact with a malicious URL and complete the login process, making social engineering a core component of the attack vector.",
  "technicalDetails": "The root cause of this vulnerability is an insecure implementation of a redirect mechanism within the Quay login workflow. Specifically, the application accepts a user-supplied parameter representing a redirect destination without performing rigorous whitelist validation or context-aware output encoding.\nWhen a user navigates to a crafted URL, the application processes the untrusted input to determine the post-login navigation path. If an attacker injects a JavaScript payload (e.g., using the 'javascript:' pseudo-protocol or other XSS vectors) into the redirect parameter, the application incorrectly trusts this input and triggers execution within the victim's browser session after successful authentication.\nThe exploitation flow is as follows: 1) An attacker crafts a URL containing a malicious redirect payload targeting the Quay authentication endpoint. 2) The attacker lures a victim into clicking the malicious link, directing them to the Quay login page. 3) The victim provides their credentials, utilizing the direct database authentication mechanism. 4) Upon successful authentication, the application performs a redirect based on the malicious input. 5) The browser interprets the injected script, executing it within the security context of the victim's session.\nBecause the execution occurs after the user has successfully authenticated, the injected script inherits the victim's privileges. This allows the attacker to perform actions with the authority of the logged-in user, potentially accessing sensitive registry data, modifying account settings, or exfiltrating session cookies. The impact is exacerbated by the fact that the script executes in a trusted, authenticated context, bypassing standard cross-origin restrictions that might otherwise apply to untrusted origins.\nThe vulnerability specifically affects Quay deployments that rely on direct database authentication. Other authentication methods may or may not be impacted depending on whether they share the same faulty redirect logic. The vulnerability is characterized as an Open Redirect leading to Stored or Reflected XSS, depending on the specific handler implementation. Since the application fails to enforce origin validation or sanitize the URL structure before the redirect navigation occurs, it provides an entry point for arbitrary client-side code execution."
}
CVE-2026-102576: Quay Open Redirect XSS Vulnerability (MEDIUM Severity, CVSS: 4.2) | Sceawere