---
id: CVE-2026-55588
title: >-
  ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in
  OCI registries
summary: >-
  ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in
  OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive
  referrer traversal does not track visited descriptors, so a malicious OCI
  registr…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-674
  - CWE-835
vendor: oras
product: oras.land/oras
affected:
  - oras.land/oras < 1.3.3
patched:
  - oras.land/oras 1.3.3
published: '2026-08-25'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:07:31.353'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55588'
references:
  - url: >-
      https://github.com/oras-project/oras/commit/440eb65d07a0631f131944d28e7c29d562ec17f3
    label: security-advisories@github.com
  - url: >-
      https://github.com/oras-project/oras/security/advisories/GHSA-298f-872v-2rcx
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55588'
  - url: 'https://github.com/advisories/GHSA-298f-872v-2rcx'
tags:
  - nvd
  - ghsa
  - go
  - score-dispute
epss: 0.00538
epssPercentile: 0.42804
aliases:
  - GHSA-298f-872v-2rcx
ecosystem: go
scores:
  nvd: 6.5
  ghsa: 2
ingestedAt: '2026-08-28T18:23:37.131Z'
---

## Overview

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph causes unbounded recursion and memory growth. This affects oras discover, whose recursive traversal is enabled by default because the --depth option defaults to 0 (unlimited), as well as the recursive referrer counting used by the oras backup and oras restore workflows. A cyclic graph can be as simple as A referring to B and B referring back to A. A malicious registry can use this to cause a client-side denial of service, exhausting CPU and memory and hanging automation or CI/CD pipelines that run ORAS against untrusted registry metadata. The vulnerability does not extend to code execution, artifact substitution, or integrity bypass. This issue has been fixed in version 1.3.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-55588)

Affected packages:

- `oras.land/oras < 1.3.3`

Patched in:

- `oras.land/oras 1.3.3`

Source: https://github.com/advisories/GHSA-298f-872v-2rcx
