Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this vulnerability, restrict network access to the `/webhooks/stripe` endpoint in Red Hat Quay. Configure network firewalls to allow connections to this endpoint only from trusted Stripe IP addresses or block access if Stripe billing integration is not utilized. This prevents unauthenticated attackers from forging billing events. Ensure any network changes are applied and services are reloaded or restarted as necessary for the changes to take effect, which may temporarily impact Quay service availability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 15 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 14 Aug 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators. | |
| Title | Quay: stripe webhook accepts forged events without signature verification in quay | |
| First Time appeared |
Redhat
Redhat openshift Update Service Redhat quay |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:/a:redhat:openshift_update_service:5 cpe:/a:redhat:quay:3 |
|
| Vendors & Products |
Redhat
Redhat openshift Update Service Redhat quay |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-14T22:43:06.490Z
Reserved: 2026-08-14T19:46:37.191Z
Link: CVE-2026-74244
No data.
Status : Received
Published: 2026-08-14T23:16:34.490
Modified: 2026-08-14T23:16:34.490
Link: CVE-2026-74244
OpenCVE Enrichment
Updated: 2026-08-15T00:30:16Z
-
CWE-347
Improper Verification of Cryptographic Signature