{"id":"CVE-2026-50151","title":"oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)","summary":"A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attac…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cvssSource":"vendor","cwe":["CWE-522","CWE-918"],"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_service_mesh 3","advanced_cluster_security 4","openshift_container_platform 4","openstack_platform 16.2","openstack_platform 17.1","openstack_platform 18.0","multicluster_global_hub 1.4.9","multicluster_global_hub 1.5.8","multicluster_global_hub 1.7.3","multicluster_global_hub 1.8.2","advanced_cluster_management_for_kubernetes 2.13"],"patched":["multicluster_global_hub 1.4.9","multicluster_global_hub 1.5.8","multicluster_global_hub 1.7.3","multicluster_global_hub 1.8.2","advanced_cluster_management_for_kubernetes 2.13"],"published":"2026-07-01","updated":"2026-09-24","sourceUpdated":"2026-09-24T17:52:56+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50151.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50151.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-50151"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2499693"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-50151"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50151"},{"url":"https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7"},{"url":"https://access.redhat.com/errata/RHSA-2026:67516"},{"url":"https://access.redhat.com/errata/RHSA-2026:71597"},{"url":"https://access.redhat.com/errata/RHSA-2026:67842"},{"url":"https://access.redhat.com/errata/RHSA-2026:68515"},{"url":"https://access.redhat.com/errata/RHSA-2026:47737"},{"url":"https://github.com/oras-project/oras-go/pull/1152"},{"url":"https://github.com/oras-project/oras-go/commit/4683c46ef078091544f5f55fd25102f002806991"},{"url":"https://github.com/oras-project/oras-go/releases/tag/v2.6.1"},{"url":"https://github.com/advisories/GHSA-jxpm-75mh-9fp7"}],"tags":["csaf","vex","red-hat","ghsa","go"],"epss":0.0049,"epssPercentile":0.39479,"ecosystem":"go","scores":{"vendor":5.9,"ghsa":7.5},"ingestedAt":"2026-07-01T22:17:35.309Z","slug":"CVE-2026-50151","body":"## Overview\n\nA flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attacker-controlled endpoint to receive the caller's credentials, leading to information disclosure. Additionally, it can enable client-side Server-Side Request Forgery (SSRF) to a cross-host target.\n\n## Vendor advisories\n\n- **RHSA-2026:67516** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67516)\n- **RHSA-2026:71597** · Red Hat · fixed in: Multicluster Global Hub 1.5.8 · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71597)\n- **RHSA-2026:67842** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67842)\n- **RHSA-2026:68515** · Red Hat · fixed in: Multicluster Global Hub 1.8.2 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68515)\n- **RHSA-2026:47737** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.13 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:47737)\n- **Red Hat VEX** · Moderate · affected: OpenShift Service Mesh 3, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0 · no fix planned: OpenShift Service Mesh 3, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50151.json)\n\n**oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload** — rated Moderate by Red Hat. Released 2026-07-01, updated 2026-09-24.\n\nAffected:\n\n- OpenShift Service Mesh 3\n- Red Hat Advanced Cluster Security 4\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat OpenStack Platform 18.0\n\nFixed:\n\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.5.8\n- Multicluster Global Hub 1.7.3\n- Multicluster Global Hub 1.8.2\n- Red Hat Advanced Cluster Management for Kubernetes 2.13\n\nNo fix planned:\n\n- OpenShift Service Mesh 3\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat OpenStack Platform 18.0\n- Red Hat Advanced Cluster Security 4\n\nNot affected:\n\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.5.8\n- Multicluster Global Hub 1.7.3\n- Multicluster Global Hub 1.8.2\n- Red Hat Advanced Cluster Management for Kubernetes 2.13\n- Gatekeeper 3\n\n## Remediation\n\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:67516\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:71597\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:67842\n\nWorkarounds / mitigations:\n\n- Upgrade to oras-go v2.6.1 or later.\n\n## Package advisory (CVE-2026-50151)\n\nAffected packages:\n\n- `oras.land/oras-go/v2 < 2.6.1`\n\nPatched in:\n\n- `oras.land/oras-go/v2 2.6.1`\n\nSource: https://github.com/advisories/GHSA-jxpm-75mh-9fp7","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206996,"id":"CVE-2026-50151","ts":1789749736014,"field":"cvss","old":"7.5","new":"5.9"},{"seq":206995,"id":"CVE-2026-50151","ts":1789749736014,"field":"severity","old":"high","new":"medium"}]}