CVE-2025-4374: Red Hat Quay

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

Affected products

  • Red Hat Quay: up to and including 3.14.0

Published 2025-05-06. Last modified 2026-08-07.