CVE-2026-85732Medium· 4.7▾ TwilightPoC availableoras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 25.9 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
0.4%
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. Tags, Referrers, and Repositories pagination operations then issue a GET request to the attacker-selected URL from the victim's network, allowing blind server-side request forgery against internal services. The response body is not returned to the attacker, but timing and error differences can reveal service reachability, and credentials may be attached when the credential store has an entry for the target host. Exploitation requires a victim to perform a pagination-based listing operation against a malicious registry. The maintainer identifies this report as a duplicate of GHSA-3hr5-mjrr-hfjh and states that remediation is consolidated in that earlier advisory. The consolidated issue is fixed in version 2.6.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
oras.land/oras-go/v2 <= 2.6.1Patched in:
oras.land/oras-go/v2 2.6.2Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85731High· 8.8oras-go is a Go library for managing OCI artifacts
CVE-2026-24117Medium· 5.3github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) (CVE-2026-24117)
CVE-2026-42043High· 7.2Axios is a promise based HTTP client for the browser and Node.js
CVE-2025-62718Critical· 9.9Axios is a promise based HTTP client for the browser and Node.js
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-12564Critical· 9.6A flaw was found in the AAP Controller's HashiCorp Vault credential plugin