<Vulnerability name="CVE-2026-85469">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-16T20:43:38</PublicDate>
    <Bugzilla id="2528219" url="https://bugzilla.redhat.com/show_bug.cgi?id=2528219" xml:lang="en:us">
quay-builder-qemu: quay-builder-qemu: Release workflow uses third-party Action pinned to mutable @master with registry credentials in scope
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.0</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-1357</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
    </Details>
    <Statement xml:lang="en:us">
This is an Important supply chain vulnerability in the build process for `quay-builder-qemu` within Red Hat Quay. The use of a mutable third-party GitHub Action with registry credentials in scope could allow an attacker to exfiltrate Quay push tokens or publish trojaned images, directly impacting the integrity of images consumed by Red Hat Quay build executors.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>quay/quay-builder-qemu-rhcos-rhel8</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-85469
https://nvd.nist.gov/vuln/detail/CVE-2026-85469
    </References>
</Vulnerability>