---
id: CVE-2026-50151
title: >-
  oras-go: oras-go: Credential forwarding via unvalidated Location header during
  blob upload (CVE-2026-50151)
summary: >-
  A flaw was found in oras-go. During the monolithic blob upload process,
  oras-go reuses the Authorization header for subsequent requests, even if a
  malicious registry provides a cross-host Location header. This vulnerability
  allows an attac…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: vendor
cwe:
  - CWE-522
  - CWE-918
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - openshift_service_mesh 3
  - advanced_cluster_security 4
  - openshift_container_platform 4
  - openstack_platform 16.2
  - openstack_platform 17.1
  - openstack_platform 18.0
  - multicluster_global_hub 1.4.9
  - multicluster_global_hub 1.5.8
  - multicluster_global_hub 1.7.3
  - multicluster_global_hub 1.8.2
  - advanced_cluster_management_for_kubernetes 2.13
patched:
  - multicluster_global_hub 1.4.9
  - multicluster_global_hub 1.5.8
  - multicluster_global_hub 1.7.3
  - multicluster_global_hub 1.8.2
  - advanced_cluster_management_for_kubernetes 2.13
published: '2026-07-01'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T17:52:56+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50151.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50151.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-50151'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2499693'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-50151'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50151'
  - url: >-
      https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7
  - url: 'https://access.redhat.com/errata/RHSA-2026:67516'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71597'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67842'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68515'
  - url: 'https://access.redhat.com/errata/RHSA-2026:47737'
  - url: 'https://github.com/oras-project/oras-go/pull/1152'
  - url: >-
      https://github.com/oras-project/oras-go/commit/4683c46ef078091544f5f55fd25102f002806991
  - url: 'https://github.com/oras-project/oras-go/releases/tag/v2.6.1'
  - url: 'https://github.com/advisories/GHSA-jxpm-75mh-9fp7'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - go
epss: 0.0049
epssPercentile: 0.39564
ecosystem: go
scores:
  vendor: 5.9
  ghsa: 7.5
ingestedAt: '2026-07-01T22:17:35.309Z'
---

## Overview

A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attacker-controlled endpoint to receive the caller's credentials, leading to information disclosure. Additionally, it can enable client-side Server-Side Request Forgery (SSRF) to a cross-host target.

## Vendor advisories

- **RHSA-2026:67516** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67516)
- **RHSA-2026:71597** · Red Hat · fixed in: Multicluster Global Hub 1.5.8 · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71597)
- **RHSA-2026:67842** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67842)
- **RHSA-2026:68515** · Red Hat · fixed in: Multicluster Global Hub 1.8.2 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68515)
- **RHSA-2026:47737** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.13 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:47737)
- **Red Hat VEX** · Moderate · affected: OpenShift Service Mesh 3, Red Hat Advanced Cluster Security 4, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0 · no fix planned: OpenShift Service Mesh 3, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50151.json)

**oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload** — rated Moderate by Red Hat. Released 2026-07-01, updated 2026-09-24.

Affected:

- OpenShift Service Mesh 3
- Red Hat Advanced Cluster Security 4
- Red Hat OpenShift Container Platform 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0

Fixed:

- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.5.8
- Multicluster Global Hub 1.7.3
- Multicluster Global Hub 1.8.2
- Red Hat Advanced Cluster Management for Kubernetes 2.13

No fix planned:

- OpenShift Service Mesh 3
- Red Hat OpenShift Container Platform 4
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0
- Red Hat Advanced Cluster Security 4

Not affected:

- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.5.8
- Multicluster Global Hub 1.7.3
- Multicluster Global Hub 1.8.2
- Red Hat Advanced Cluster Management for Kubernetes 2.13
- Gatekeeper 3

## Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:67516
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:71597
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:67842

Workarounds / mitigations:

- Upgrade to oras-go v2.6.1 or later.

## Package advisory (CVE-2026-50151)

Affected packages:

- `oras.land/oras-go/v2 < 2.6.1`

Patched in:

- `oras.land/oras-go/v2 2.6.1`

Source: https://github.com/advisories/GHSA-jxpm-75mh-9fp7
