oras.land/oras-go
Activity
- Latest release
- 11mo ago
- Total releases
- 20
- Cadence
- ~2 months
- Last 12 months
- 1
Details
- First release
- May 04, 2021
| Version | Released | |
|---|---|---|
v1.2.7
patch
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.2.7
patch
Dependencies (15)
+ 7 more |
|
v1.2.6
patch
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.2.6
patch
Dependencies (15)
+ 7 more |
|
v1.2.5
patch
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.2.5
patch
Dependencies (15)
+ 7 more |
|
v1.2.4
patch
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.2.4
patch
Dependencies (15)
+ 7 more |
|
v1.2.3
patch
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.2.3
patch
Dependencies (15)
+ 7 more |
|
v1.2.2
patch
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (15)
+ 7 more |
|
v1.2.1
patch
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (15)
+ 7 more |
|
v1.2.0
minor
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (15)
+ 7 more |
|
v1.1.1
patch
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (13)
+ 5 more |
|
v1.1.0-rc3
pre
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.1.0-rc3
pre
Dependencies (13)
+ 5 more |
|
v1.1.0
minor
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (13)
+ 5 more |
|
v1.1.0-rc2
pre
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.1.0-rc2
pre
Dependencies (13)
+ 5 more |
|
v1.1.0-rc1
pre
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.1.0-rc1
pre
Dependencies (13)
+ 5 more |
|
v1.0.0
major
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (13)
+ 5 more |
|
v0.5.0
minor
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (13)
+ 5 more |
|
v0.4.0
minor
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (12)
+ 4 more |
|
v0.3.0
minor
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (12)
+ 4 more |
|
v0.3.0-rc1
pre
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v0.3.0-rc1
pre
Dependencies (12)
+ 4 more |
|
v0.2.0
minor
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (12)
+ 4 more |
|
v0.1.0
initial
1 CVE
CVE-2026-48978
GHSA-xf85-363p-868w
GO-2026-5885
Jul 01, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
Network
High
None
Summaryoras-go's
What is NOT claimedThis advisory does not claim that credential forwarding to an arbitrary public attacker host through a server-controlled realm is, on its own, a vulnerability. The distribution spec defines Affected versions
SeverityMedium. Network attack vector, low complexity, no privileges required, user interaction required (victim runs an oras command against the malicious or MITM'd registry), unchanged scope. Confidentiality impact is limited — IMDS probe responses can disclose information, and TLS downgrade exposes the realm request to passive observers — but the attacker does not obtain credentials beyond what the malicious endpoint already controls. Affected code
The CWE
Patch
Cross-host realms on public DNS names continue to be accepted. CreditReported by bugbunny.ai. References Updated Sep 10, 2026 · Source: OSV.dev |
v0.1.0
initial
Dependencies (13)
+ 5 more |