CVE-2026-74247: Red Hat Openshift Update Service

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.

Affected products

  • Red Hat Openshift Update Service: affected versions not specified
  • Red Hat Quay: version 3.0.0 only

Published 2026-08-14. Last modified 2026-08-20.