- Issued:
- 2026-06-02
- Updated:
- 2026-06-02
RHSA-2026:22465 - Security Advisory
Synopsis
Red Hat Quay 3.17.2
Type/Severity
Security Advisory: Important
Topic
Red Hat Quay 3.17.2 is now available with bug fixes.
Description
Quay 3.17.2
Solution
Before applying this update, make sure all previously released errata relevant
to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Quay
Fixes
- PROJQUAY-10510 - Quay new UI Verify User can't sign in with OIDC provider
- PROJQUAY-10575 - Cancel Repository Mirroring log: null Not applicable Not applicable
- PROJQUAY-10873 - Mirror pods will be terminated and cannot be restarted after the securityContext is overwritten
- PROJQUAY-10931 - "None" option in repository permissions dropdown menu can't be selected in Create robot account pop-up window
- PROJQUAY-11162 - Clair's indexer needs O_TMPFILE for cleanup
- PROJQUAY-11175 - Cancel a organization mirror process will trigger an endless stream of log "Organization mirror sync failed - Sync cancelled:" [3.17]
- PROJQUAY-11205 - Quay's is_jwt() rejects RFC 9068 access tokens with typ: at+jwt
- PROJQUAY-11236 - The string entered in the repository filter will automatically be displayed in unreasonable places
- PROJQUAY-11297 - [redhat-3.17] Quay new UI Login page branding logo is invisible
- PROJQUAY-11330 - Quay 3.17 New UI change_tag_immutability action missing from usage logs chart
- PROJQUAY-11332 - config-tool: malformed struct tag on DistributedStorageArgs.Signature breaks storage config serialization
- PROJQUAY-11333 - Ensure that we don't send artifacts for scanning
- PROJQUAY-11374 - "None" option in repository permissions dropdown menu can't be selected in Create robot account pop-up window
- PROJQUAY-11392 - Deleting org mirror config leaves repositories stuck in ORG_MIRROR state
- PROJQUAY-11414 - Org mirror "Cancel Sync" clean the "Next Sync Date" value
- PROJQUAY-11442 - Quay new UI: manifest track vertical line appears on pages where no tags share the same digest
- PROJQUAY-11485 - UI disallows creation of proxy configuration even if organization mirroring is turned off
- PROJQUAY-11502 - Searching for a non-existent repository will permanently display a circular loading spinner on the page
- PROJQUAY-11504 - Cancel Repository Mirroring log: null Not applicable Not applicable
- PROJQUAY-11523 - Repo Mirror tag pattern change requires re-entering credentials for private repos
- PROJQUAY-11532 - nginx returns a 404 http code instead of 502 due to missing 502.html page
- PROJQUAY-11543 - Quay new UI Verify User can't sign in with OIDC provider
- PROJQUAY-11559 - Quay 3.17.2 New UI superuser Change Log page missing v3.17.2 release notes
- PROJQUAY-7340 - Passwords exposed in skopeo commands
CVEs
- CVE-2025-62718
- CVE-2026-27459
- CVE-2026-29063
- CVE-2026-29074
- CVE-2026-32280
- CVE-2026-32281
- CVE-2026-32282
- CVE-2026-32286
- CVE-2026-32589
- CVE-2026-32590
- CVE-2026-33186
- CVE-2026-33747
- CVE-2026-33894
- CVE-2026-34986
- CVE-2026-39892
- CVE-2026-40192
- CVE-2026-40895
- CVE-2026-42033
- CVE-2026-42035
- CVE-2026-42039
- CVE-2026-42041
- CVE-2026-42043
- CVE-2026-42044
- CVE-2026-4427
amd64
| registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:4aea7185e69a0d0c235cb7d1ee55c9bf4336fe8c2a5a911a9e298d56673f847c |
| registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:0db0854b0aebfbc40f819ee94fadea510ed5b8294a16af0eee88880129d52587 |
| registry.redhat.io/quay/quay-bridge-operator-bundle@sha256:844173e5e8d469ff53b4741735f12c262f70122a83e1a3b44287633f87d922f9 |
| registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:53294b9f3b327dcd9cd5e2188d0ee4b0861c00923421de85319f2dc442ce7508 |
| registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:8dded1d8b749a07ff9400399ba8a005d59258eb896b9ff66014587e5b8dd63f6 |
| registry.redhat.io/quay/quay-builder-rhel9@sha256:e2e5b4773f22bf9205096f15b3a2275f748c0c3f00f1c480e4f336615a5cea91 |
| registry.redhat.io/quay/clair-rhel9@sha256:c38a3a6547c9da624e72c0a5092fba5668a66a9b2f440808b8b6f100fa1d1ae8 |
| registry.redhat.io/quay/quay-operator-bundle@sha256:706312389cb29f050fbb20ad327d0cdd2adc526fb32346abe1a6e98d64323bfd |
| registry.redhat.io/quay/quay-operator-rhel9@sha256:eb037e300339377b57b964f05c5988b3d8f5a1a8fb63a3e167de6b68dc875e1f |
| registry.redhat.io/quay/quay-rhel9@sha256:8c7f4a453b3414c2d3457f2a8c65b67c70dd55e4bf7a31a9f3674865af5e1da1 |
arm64
| registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:b3b93f33b172be548f93e48755e0a88e88de33cbe2d65858ee93c5c5fefa5c1f |
| registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:07ac14b5985a6d1aab2ad58d0ed6fcd94a538de1c9bd171bc4a4162b2ade6a62 |
| registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:7914cfbd30aa0ca0a25b72387ef420879f6eb890b607c88b75f6aa1c9528ed2a |
| registry.redhat.io/quay/quay-builder-rhel9@sha256:805855fd0e19fcb41d0ee649196ac2eefd19a7af1394c643d1981db033517e27 |
| registry.redhat.io/quay/clair-rhel9@sha256:3a55b3ec35c4a8e6359043566b86376871be774355cf8f09b442b268b5f2243a |
| registry.redhat.io/quay/quay-operator-rhel9@sha256:ce7a9853fdd031d67e796becced393855e1944ecd9e8acb2d589403834d0b7f1 |
| registry.redhat.io/quay/quay-rhel9@sha256:a24c973edd52d4a418d415d54108cf44f495a969db1d0f6e5b6149e0a6021110 |
ppc64le
| registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:d59de91f679cc4b70d2093d717dbdf3f8bef7322de1d43f7db2470cff1f022e0 |
| registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:b6ca818876d348e6204c808d141be0190946279851a00eb4211888e945c90f80 |
| registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:f932e889884451edf02937c8c7b858c15542d8f49bed07414c01e9bf4e879bd4 |
| registry.redhat.io/quay/quay-builder-rhel9@sha256:466b8c2341eb4d2f6c6dd02c7403e5d96fb011b192b9d3bd1d9519855dee1e5c |
| registry.redhat.io/quay/clair-rhel9@sha256:97f144ef4b31ee6cfb154555c6f15ef4184bebf9298b440eb604228435513c79 |
| registry.redhat.io/quay/quay-operator-rhel9@sha256:18eda16fdd54b45a3fe484542d20fb1b1b4fd5b9e38c79d70dc11b4c0e1bab03 |
| registry.redhat.io/quay/quay-rhel9@sha256:9e4588550a0e266f7598eb4af1dd020629357ffd305a02d8e7765114c7210812 |
s390x
| registry.redhat.io/quay/quay-container-security-operator-rhel9@sha256:e1d6574191585e5cc4416c8c6efd5b4dad26b6dba4c54ca4008f8d314d59145d |
| registry.redhat.io/quay/quay-bridge-operator-rhel9@sha256:8e927b2102b2d5cd45629790d16c5ada1cc327b6a64acb33d36e2c4f7fbd9912 |
| registry.redhat.io/quay/quay-builder-qemu-rhcos-rhel8@sha256:8838c17d3bb0b1490e23866c3ebc3a7c212d381aab4df0d519a8ea2d6099ae3b |
| registry.redhat.io/quay/quay-builder-rhel9@sha256:661fb709bf1bf1b391534159a8df1567245cc791f069035f3c6531ee536cebf8 |
| registry.redhat.io/quay/clair-rhel9@sha256:5821c6d9fc1efb01b375cd59017be0ab7adb1794e8ab92b03387e7930d73fd75 |
| registry.redhat.io/quay/quay-operator-rhel9@sha256:d05c09022220346d62bc4dc57984c7368994d317d5745139191d6aba70599883 |
| registry.redhat.io/quay/quay-rhel9@sha256:65c631d107c264bef8a74336077b413609da4cfc37c8c9488afdcaa0df07dad5 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.