{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ared_hatquay_builder_qemu/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:red_hat:quay_builder_qemu:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8,"id":"CVE-2026-85469"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["quay-builder-qemu"],"_cs_severities":["high"],"_cs_tags":["supply-chain","ci-cd","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-85469 describes a supply chain vulnerability affecting quay-builder-qemu, stemming from the inclusion of the third-party GitHub Action \u003ccode\u003eNoelware/docker-manifest-action\u003c/code\u003e in the project's release workflow. The workflow pins this dependency to a mutable branch rather than a specific immutable commit hash, creating a vector for dependency confusion or upstream compromise.\u003c/p\u003e\n\u003cp\u003eIf an attacker compromises the upstream Noelware repository, they can inject arbitrary malicious code that executes within the build environment. This process facilitates the exfiltration of sensitive registry credentials and the potential poisoning of container images produced by the build pipeline. Furthermore, the workflow configuration improperly exposes the default GitHub Actions token, which an attacker can leverage to further compromise the repository or associated infrastructure. This vulnerability highlights the significant risk posed by mutable dependencies in automated CI/CD pipelines.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to gain control over the build process, resulting in the theft of registry credentials and the injection of backdoored container images into the software supply chain. This impact extends to the integrity of any downstream systems or clients that deploy images built by the compromised pipeline.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for CI/CD pipeline security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all GitHub Action workflows for dependencies pinned to mutable tags or branches.\u003c/li\u003e\n\u003cli\u003ePin all third-party GitHub Actions to specific, immutable SHA-256 commit hashes to prevent execution of unauthorized code.\u003c/li\u003e\n\u003cli\u003eAudit workflow permissions to adhere to the principle of least privilege, specifically restricting access to secrets and the default GITHUB_TOKEN.\u003c/li\u003e\n\u003cli\u003eMonitor CI/CD logs for unexpected network connections originating from build runners, particularly those targeting credential storage or external file hosting services.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T23:52:21Z","date_published":"2026-09-16T23:52:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-quay-builder-qemu-supply-chain/","summary":"A supply chain vulnerability in quay-builder-qemu allows for remote code execution and credential theft due to the use of a mutable GitHub Action dependency.","title":"Supply Chain Vulnerability in quay-builder-qemu via Mutable GitHub Action","url":"https://feed.craftedsignal.io/briefs/2026-09-quay-builder-qemu-supply-chain/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:red_hat:quay_builder_qemu:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}