v3.10.25
📦 quay-ioView on GitHub →
🐛 5 fixes🔧 5 symbols
Summary
This release addresses several CVEs by upgrading dependencies like pyasn1 and pillow, and patching vulnerabilities in decode-uri-component, brace-expansion, and js-yaml. It also includes a fix to prevent SSRF in repository sources.
🐛 Bug Fixes
- CVE-2026-45822: Fixed a vulnerability in decode-uri-component.
- CVE-2026-59885: Upgraded pyasn1 to 0.6.4 to address a vulnerability.
- CVE-2026-13149: Addressed a vulnerability in brace-expansion.
- CVE-2026-59869: Addressed a vulnerability in js-yaml.
- PROJQUAY-12356: Prevented SSRF in repository sources.