CVE-2026-50162Medium· 5.3▾ SunlitA flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob tit…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
Last analysed / modified upstream
— → 5.3
A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob title, could exploit this vulnerability to create files outside the intended working directory. This filesystem boundary bypass allows for arbitrary file creation, potentially leading to unauthorized data modification or system compromise depending on the runtime environment.
oras-go: oras-go: File store write outside working directory via symlink traversal — rated Moderate by Red Hat. Released 2026-07-01, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:68044 See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:68253 See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.2 https://access.redhat.com/errata/RHSA-2026:68006
Affected packages:
oras.land/oras-go/v2 < 2.6.1Patched in:
oras.land/oras-go/v2 2.6.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42306High· 7.2github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup (…
CVE-2026-15801High· 8.0A vulnerability was found in CRI-O related to the container checkpoint and restore feature
CVE-2023-27534Low· 3.7curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)
CVE-2026-81829Medium· 5.3A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers
CVE-2026-79705Medium· 4.5A flaw was found in the buildah/copier Go package
CVE-2025-59682High· 8.8django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)