CVE-2026-50151Medium· 5.9▾ SunlitA flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attac…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
7.5 → 5.9
high → medium
Last analysed / modified upstream
A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attacker-controlled endpoint to receive the caller's credentials, leading to information disclosure. Additionally, it can enable client-side Server-Side Request Forgery (SSRF) to a cross-host target.
oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload — rated Moderate by Red Hat. Released 2026-07-01, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:67516 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:67842 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:68515
Workarounds / mitigations:
Affected packages:
oras.land/oras-go/v2 < 2.6.1Patched in:
oras.land/oras-go/v2 2.6.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49478High· 8.7Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity
CVE-2021-33194High· 7.5golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)
CVE-2022-23526High· 7.5helm: Denial of service through schema file (CVE-2022-23526)
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)
CVE-2026-56855Medium· 5.3golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages (CVE-2026-56855)
CVE-2026-78662Medium· 5.3golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding (CVE-2026-78662)