CVE-2026-32590
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the d
CVSS
7.1
High
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Apr 8, 2026 · Last modified: Jul 19, 2026 · CWE-502
0.4%EPSS · 30 days0.4%
2026-06-302026-07-20
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19375
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:21017
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22465
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22629
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22840
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:23361
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24833
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24853
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:28441
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-32590
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2446964
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-422379.8 CRI99.9%
KEV—80Sitecore XP Remote Command Execution Vulnerability12dCVE-2026-456598.8 HIG86.8%
KEV—76Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability19dCVE-2026-586449.8 CRI70.8%
KEV—71Microsoft SharePoint Deserialization of Untrusted Data Vulnerability4dCVE-2026-125699.8 CRI66.0%
KEV—70PTC Windchill and FlexPLM Improper Input Validation Vulnerability20dCVE-2026-505229.8 CRI97.2%
——29Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.5dCVE-2025-560059.8 CRI96.7%
——29An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `pickle` allows execution of embedded code via `__reduce__()`, an attacker can achieve code execution by passing a malicious pickle file. The parameter is not mentioned in official documentation or the GitHub repository, yet it is active in the PyPI version. This introduces a stealthy backdoor and persistence risk. NOTE: A third-party states that this vulnerability should be rejected because the proof of concept does not demonstrate arbitrary code execution and fails to complete successfully.15h