{"apiVersion":"1.0","identifier":"CVE-2026-74244","description":"A flaw was found in Red Hat Quay-s Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace-s build quota to its maximum and trigger unsolicited billing emails to namespace administrators.","publishedAt":"2026-08-14T23:16:34","lastModifiedAt":"2026-08-20T20:01:38","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74244","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","epssProbability":0.00141,"riskScore":0.6,"affectedProduct":"Red Hat Quay","affectedVersions":"unknown","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74244","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74244","en":"https://www.redsauce.net/en/cves/CVE-2026-74244","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74244","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74244","de":"https://www.redsauce.net/de/cves/CVE-2026-74244","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74244","el":"https://www.redsauce.net/el/cves/CVE-2026-74244"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74244"}}