CVE-2026-102295: Red Hat Quay 3
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaScript code within a user's browser session. By tricking a logged-in user into visiting a specially crafted link, an attacker can exploit improper input sanitization to run client-side scripts in the application context. Successful exploitation could allow the attacker to compromise the user's session, access sensitive registry information, or perform unauthorized actions on their behalf.
Affected products
- Red Hat Red Hat Quay 3
Published 2026-10-05. Last modified 2026-10-06.