GO-2026-5884None▾ SunlitORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
oras.land/oras-go/v2 < 2.6.1Upgrade to a patched release:
oras.land/oras-go/v2 2.6.1Connected by shared product, vendor, weakness, or advisory.
GHSA-vh4v-2xq2-g5cgMediumORAS Go forwards registry credentials across registry redirects
CVE-2026-48978Loworas-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
CVE-2026-50163High· 7.1`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution