5.8
MEDIUM CVSS 3.1
CVE-2026-10517
Clair: clair: unauthenticated ssrf via manifest layer uri enables internal network reconnaissance
Description

Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is implemented entirely in github.com/quay/clair; no PSK-related code exists anywhere in claircore's codebase or git history. The unauthenticated indexer API is Clair's documented, intentional design, authentication is an opt-in deployment choice, not a code defect. No fix commit was found in claircore between the version recorded as the affected boundary (1.5.52) and the following release (1.5.53); intervening commits are unrelated dependency and feature changes, so the "fixed in 1.5.52" status is inaccurate.

INFO

Published Date :

June 1, 2026, 9:16 a.m.

Last Modified :

July 27, 2026, 9:16 a.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2026-10517 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Redhat quay
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 MEDIUM 53f830b8-0a3f-465b-8143-3b8a9948e749
CVSS 3.1 MEDIUM [email protected]
Solution
Configure PSK authentication or restrict HTTP request sources to mitigate SSRF.
  • Configure PSK authentication for the fetcher component.
  • Restrict HTTP request sources to authorized endpoints.
  • Update Clair to the latest version.
  • Apply vendor-specific hardening guides.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-10517 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-10517 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by [email protected]

    Jul. 27, 2026

    Action Type Old Value New Value
    Changed Description A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. When PSK authentication is not configured (opt-in, not enforced by default), an unauthenticated attacker can submit a manifest with a URI pointing to internal services or cloud metadata endpoints. The SSRF is reflective for non-200 responses, leaking up to 256 bytes of error body content via CheckResponse error messages. Operator-managed Red Hat Quay deployments auto-configure PSK and are not exposed to the unauthenticated attack vector. Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is implemented entirely in github.com/quay/clair; no PSK-related code exists anywhere in claircore's codebase or git history. The unauthenticated indexer API is Clair's documented, intentional design, authentication is an opt-in deployment choice, not a code defect. No fix commit was found in claircore between the version recorded as the affected boundary (1.5.52) and the following release (1.5.53); intervening commits are unrelated dependency and feature changes, so the "fixed in 1.5.52" status is inaccurate.
    Removed CVSS V3.1 Red Hat, Inc.: AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
    Removed CWE Red Hat, Inc.: CWE-918
    Removed Reference Red Hat, Inc.: https://access.redhat.com/security/cve/CVE-2026-10517
    Removed Reference Red Hat, Inc.: https://bugzilla.redhat.com/show_bug.cgi?id=2486779
    Removed Affected [{'cpes': ['cpe:/a:redhat:quay:3'], 'vendor': 'Red Hat', 'product': 'Red Hat Quay 3', 'packageName': 'quay/clair-rhel8', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:quay:3'], 'vendor': 'Red Hat', 'product': 'Red Hat Quay 3', 'packageName': 'quay/clair-rhel9', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}]
  • CVE Rejected by [email protected]

    Jul. 27, 2026

    Action Type Old Value New Value
  • CVE Translated by [email protected]

    Jul. 22, 2026

    Action Type Old Value New Value
    Added Translation Title: Red Hat Quay 3 de Red Hat, Description: Se encontró una vulnerabilidad en Clair. El componente 'fetcher' realiza solicitudes HTTP salientes a URIs proporcionadas por el atacante desde descriptores de capas de manifiesto sin filtrado de IP o esquema. Cuando la autenticación PSK no está configurada (opcional, no aplicada por defecto), un atacante no autenticado puede enviar un manifiesto con una URI que apunta a servicios internos o puntos finales de metadatos en la nube. La SSRF es reflectiva para respuestas que no son 200, filtrando hasta 256 bytes de contenido del cuerpo del error a través de mensajes de error de CheckResponse. Las implementaciones de Red Hat Quay gestionadas por operadores auto-configuran PSK y no están expuestas al vector de ataque no autenticado.
  • CVE Modified by [email protected]

    Jun. 26, 2026

    Action Type Old Value New Value
    Added Reference https://bugzilla.redhat.com/show_bug.cgi?id=2486779
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jun. 17, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2026-10517', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-06-01T10:21:59.947029Z'}
  • CVE Modified by [email protected]

    Jun. 17, 2026

    Action Type Old Value New Value
    Added Affected [{'cpes': ['cpe:/a:redhat:quay:3'], 'vendor': 'Red Hat', 'product': 'Red Hat Quay 3', 'packageName': 'quay/clair-rhel8', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:quay:3'], 'vendor': 'Red Hat', 'product': 'Red Hat Quay 3', 'packageName': 'quay/clair-rhel9', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}]
  • New CVE Received by [email protected]

    Jun. 01, 2026

    Action Type Old Value New Value
    Added Description A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. When PSK authentication is not configured (opt-in, not enforced by default), an unauthenticated attacker can submit a manifest with a URI pointing to internal services or cloud metadata endpoints. The SSRF is reflective for non-200 responses, leaking up to 256 bytes of error body content via CheckResponse error messages. Operator-managed Red Hat Quay deployments auto-configure PSK and are not exposed to the unauthenticated attack vector.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
    Added CWE CWE-918
    Added Reference https://access.redhat.com/security/cve/CVE-2026-10517
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.