oras-go vulnerabilities
CVEs whose affected-version data names the oras-go package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-85732Medium· 4.7PoCoras-go is a Go library for managing OCI artifacts
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. …
▾ Twilightoras-project · oras-goEPSS 0.38%via NVD
CVE-2026-85731High· 8.8PoCoras-go is a Go library for managing OCI artifacts
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractT…
▾ Midnightoras-project · oras-goEPSS 0.67%via NVD