---
id: CVE-2026-50162
title: >-
  oras-go: oras-go: File store write outside working directory via symlink
  traversal (CVE-2026-50162)
summary: >-
  A flaw was found in oras-go. The file content store, intended to confine
  writes to a specified working directory, does not properly account for
  symbolic link (symlink) traversal. A remote attacker, by providing a specially
  crafted blob tit…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cvssSource: vendor
cwe:
  - CWE-22
  - CWE-73
vendor: Red Hat
product: Red Hat Edge Manager 1.1
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - mcp_server_for_red_hat_openshift
  - migration_toolkit_for_virtualization
  - openshift_lightspeed
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 4
  - ceph_storage 9
  - developer_hub
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_data_foundation 4
  - openshift_gitops
  - openshift_virtualization 4
  - trusted_artifact_signer
  - trusted_profile_analyzer
  - web_terminal
  - security_profiles_operator
  - edge_manager 1.1
  - edge_manager 1.2
  - hardened_images
patched:
  - edge_manager 1.1
  - edge_manager 1.2
  - hardened_images
published: '2026-07-01'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T01:36:11+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50162.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50162.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-50162'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2499694'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-50162'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50162'
  - url: >-
      https://github.com/oras-project/oras-go/security/advisories/GHSA-8xwf-rjm4-xvhv
  - url: 'https://access.redhat.com/errata/RHSA-2026:68044'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68253'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68006'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68254'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42241'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42230'
  - url: >-
      https://github.com/oras-project/oras-go/commit/cc323e564d90c6b5b4bdd71d3c8d2ee2713b37e5
  - url: 'https://github.com/advisories/GHSA-8xwf-rjm4-xvhv'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - go
epss: 0.00507
epssPercentile: 0.40708
ecosystem: go
ingestedAt: '2026-07-01T22:17:35.221Z'
---

## Overview

A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob title, could exploit this vulnerability to create files outside the intended working directory. This filesystem boundary bypass allows for arbitrary file creation, potentially leading to unauthorized data modification or system compromise depending on the runtime environment.

## Vendor advisories

- **RHSA-2026:68044** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68044)
- **RHSA-2026:68253** · Red Hat · fixed in: Red Hat Edge Manager 1.1 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68253)
- **RHSA-2026:68006** · Red Hat · fixed in: Red Hat Edge Manager 1.2 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68006)
- **RHSA-2026:68254** · Red Hat · fixed in: Red Hat Edge Manager 1.2 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68254)
- **RHSA-2026:42241** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42241)
- **RHSA-2026:42230** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42230)
- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, MCP Server for Red Hat OpenShift, Migration Toolkit for Virtualization, OpenShift Lightspeed, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Security 4, … · no fix planned: MCP Server for Red Hat OpenShift, Red Hat Advanced Cluster Security 4, Red Hat Developer Hub, Red Hat OpenShift GitOps, … · updated 2026-09-26 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50162.json)

**oras-go: oras-go: File store write outside working directory via symlink traversal** — rated Moderate by Red Hat. Released 2026-07-01, updated 2026-09-26.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- MCP Server for Red Hat OpenShift
- Migration Toolkit for Virtualization
- OpenShift Lightspeed
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ceph Storage 9
- Red Hat Developer Hub
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat Trusted Artifact Signer
- Red Hat Trusted Profile Analyzer
- Red Hat Web Terminal
- Security Profiles Operator

Fixed:

- Red Hat Edge Manager 1.1
- Red Hat Edge Manager 1.2
- Red Hat Hardened Images

No fix planned:

- MCP Server for Red Hat OpenShift
- Red Hat Advanced Cluster Security 4
- Red Hat Developer Hub
- Red Hat OpenShift GitOps
- Red Hat Ceph Storage 9
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift Virtualization 4
- Red Hat Trusted Profile Analyzer
- Red Hat Web Terminal
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Migration Toolkit for Virtualization
- OpenShift Lightspeed
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Trusted Artifact Signer
- Security Profiles Operator

Not affected:

- Red Hat Edge Manager 1.1
- Red Hat Edge Manager 1.2
- Deployment Validation Operator
- Gatekeeper 3
- Multicluster Global Hub
- OpenShift Developer Tools and Services
- OpenShift Service Mesh 3
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Edge Manager 1

## Remediation

See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:68044
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:68253
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.2 https://access.redhat.com/errata/RHSA-2026:68006

## Package advisory (CVE-2026-50162)

Affected packages:

- `oras.land/oras-go/v2 < 2.6.1`

Patched in:

- `oras.land/oras-go/v2 2.6.1`

Source: https://github.com/advisories/GHSA-8xwf-rjm4-xvhv
