CVE-2026-2376Disclosure(redhat / enterprise_linux)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • mirror_registry
  • quay

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
enterprise_linuxmirror_registryquay

4 versions affected across 3 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-12: 1Technical Details · 2026-03-12: 103-12
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-2376 A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web… https://www.cve.org/CVERecord?id=CVE-2026-2376

    Post summary

    The notice announces a newly identified flaw in mirror-registry that allows authenticated users to gain unintended access to internal systems by providing malicious web content, but no proof of concept, exploit, active exploitation, patch, or false positive claim is mentioned.

    00000133
    56.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhatmirror_registry-openshift-
Appredhatquay3.0.0--

Explore more