A flaw was found in Red Hat Quay's Stripe billing webhook...
Moderate severity
Unreviewed
Published
Aug 15, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Aug 14, 2026
Published to the GitHub Advisory Database
Aug 15, 2026
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the
/webhooks/stripeendpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators.References