oras-go has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was July 2026 with 4. The median CVSS is 7.1 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-50163High· 7.1`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution39GHSA-vh4v-2xq2-g5cgMediumORAS Go forwards registry credentials across registry redirects28CVE-2026-48978Loworas-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens14GO-2026-5884NoneORAS Go forwards registry credentials across registry redirects in oras.land/oras-go3
oras-go vulnerabilities
CVEs affecting oras-go, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
GO-2026-5884NoneORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
▾ Sunlitoras-go · oras.land/oras-go/v2via OSV
CVE-2026-50163High· 7.1`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
▾ Twilightoras-go · oras.land/oras-go/v2EPSS 0.35%via GHSA
GHSA-vh4v-2xq2-g5cgMediumORAS Go forwards registry credentials across registry redirects
ORAS Go forwards registry credentials across registry redirects
▾ Sunlitoras-go · oras.land/oras-go/v2via GHSA
CVE-2026-48978Loworas-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
▾ Sunlitoras-go · oras.land/oras-go/v2EPSS 0.26%via GHSA