oras.land/oras-go/v2 vulnerabilities
CVEs whose affected-version data names the oras.land/oras-go/v2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
GO-2026-5884NoneORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
▾ Sunlitoras-go · oras.land/oras-go/v2via OSV
CVE-2026-50163High· 7.1`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
▾ Twilightoras-go · oras.land/oras-go/v2EPSS 0.43%via GHSA
GHSA-vh4v-2xq2-g5cgMediumORAS Go forwards registry credentials across registry redirects
ORAS Go forwards registry credentials across registry redirects
▾ Sunlitoras-go · oras.land/oras-go/v2via GHSA
CVE-2026-48978Loworas-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
▾ Sunlitoras-go · oras.land/oras-go/v2EPSS 0.26%via GHSA