Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Wed, 16 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise. | |
| Title | Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope | |
| First Time appeared |
Redhat
Redhat quay |
|
| Weaknesses | CWE-1357 | |
| CPEs | cpe:/a:redhat:quay:3 | |
| Vendors & Products |
Redhat
Redhat quay |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-16T21:42:23.826Z
Reserved: 2026-09-03T20:10:49.398Z
Link: CVE-2026-85469
No data.
Status : Received
Published: 2026-09-16T22:18:27.037
Modified: 2026-09-16T22:18:27.037
Link: CVE-2026-85469
No data.
OpenCVE Enrichment
No data.