oras.land/oras-go/v2
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting oras.land/oras-go/v2page 1 of 1
- CVE-2026-48978LOWCVSS 2.1EG 2.1✓ Fixed in 2.6.12026-07-01
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry …
- CVE-2026-50151HIGHCVSS 7.5EG 7.5✓ Fixed in 2.6.12026-07-01
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authoriz…
- CVE-2026-50162MEDIUMCVSS 6.9EG 6.9✓ Fixed in 2.6.12026-07-01
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=f…
- CVE-2026-50163HIGHCVSS 7.1EG 7.12026-07-01
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret"…
Check whether oras.land/oras-go/v2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for oras.land/oras-go/v2 CVEs against the assets you own.
Start Free Scan →