meifukun (https://github.com/meifukun)
7 credited records · 7 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2026-74247No exploit | Quay: ssrf via build archive_url in quay build apiredhat · openshift update service · CWE-918 | High7.1 | — | 0.2% | Aug 14, 2026 |
30Monitor | CVE-2026-74245No exploit | Quay: unauthenticated exported logs download in quayredhat · openshift update service · CWE-306 | High7.5 | — | 0.4% | Aug 14, 2026 |
30Monitor | CVE-2026-74244No exploit | Quay: stripe webhook accepts forged events without signature verification in quayredhat · openshift update service · CWE-347 | High7.5 | — | 0.2% | Aug 14, 2026 |
32Monitor | CVE-2026-74243No exploit | Quay: unauthenticated secscan notification endpoint in quay when psk is unsetredhat · openshift update service · CWE-306 | High8.2 | — | 0.5% | Aug 14, 2026 |
17Monitor | CVE-2026-74242No exploit | Quay: repository notification uuid idor in quay apiredhat · openshift update service · CWE-639 | Medium4.4 | — | 0.3% | Aug 14, 2026 |
26Monitor | CVE-2026-74241No exploit | Quay: ldap referral filter injection in quay external ldap authenticationredhat · openshift update service · CWE-90 | Medium6.5 | — | 0.3% | Aug 14, 2026 |
21Monitor | CVE-2026-74240No exploit | Quay: jwt claim validation bypasses in quay federated robot and sso authenticationredhat · openshift update service · CWE-287 | Medium5.4 | — | 0.3% | Aug 14, 2026 |
- CVE-2026-7424728Monitor
Quay: ssrf via build archive_url in quay build api
HighCVSS 7.1No exploitEPSS 0%redhat · openshift update serviceAug 14, 2026
- CVE-2026-7424530Monitor
Quay: unauthenticated exported logs download in quay
HighCVSS 7.5No exploitEPSS 0%redhat · openshift update serviceAug 14, 2026
- CVE-2026-7424430Monitor
Quay: stripe webhook accepts forged events without signature verification in quay
HighCVSS 7.5No exploitEPSS 0%redhat · openshift update serviceAug 14, 2026
- CVE-2026-7424332Monitor
Quay: unauthenticated secscan notification endpoint in quay when psk is unset
HighCVSS 8.2No exploitEPSS 0%redhat · openshift update serviceAug 14, 2026
- CVE-2026-7424217Monitor
Quay: repository notification uuid idor in quay api
MediumCVSS 4.4No exploitEPSS 0%redhat · openshift update serviceAug 14, 2026
- CVE-2026-7424126Monitor
Quay: ldap referral filter injection in quay external ldap authentication
MediumCVSS 6.5No exploitEPSS 0%redhat · openshift update serviceAug 14, 2026
- CVE-2026-7424021Monitor
Quay: jwt claim validation bypasses in quay federated robot and sso authentication
MediumCVSS 5.4No exploitEPSS 0%redhat · openshift update serviceAug 14, 2026