oras.land/oras-go/v2
Activity
- Latest release
- 2mo ago
- Total releases
- 20
- Cadence
- ~37 days
- Last 12 months
- 2
Details
- First release
- Jun 24, 2022
| Version | Released | |
|---|---|---|
v2.6.2
patch
|
v2.6.2
patch
Dependencies (3)
|
|
v2.6.1
patch
1 CVE
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev |
v2.6.1
patch
Dependencies (3)
|
|
v2.6.0
minor
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.6.0
minor
Dependencies (3)
|
|
v2.5.0
minor
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.5.0
minor
Dependencies (3)
|
|
v2.4.0
minor
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.4.0
minor
Dependencies (3)
|
|
v2.3.1
patch
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.3.1
patch
Dependencies (3)
|
|
v2.3.0
minor
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.3.0
minor
Dependencies (3)
|
|
v2.2.1
patch
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.2.1
patch
Dependencies (3)
|
|
v2.2.0
minor
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.2.0
minor
Dependencies (3)
|
|
v2.1.0
minor
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.1.0
minor
Dependencies (3)
|
|
v2.0.2
patch
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.2
patch
Dependencies (3)
|
|
v2.0.1
patch
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.1
patch
Dependencies (3)
|
|
v2.0.0
initial
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0
initial
Dependencies (3)
|
|
v2.0.0-rc.6
pre
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.6
pre
Dependencies (3)
|
|
v2.0.0-rc.5
pre
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.5
pre
Dependencies (3)
|
|
v2.0.0-rc.4
pre
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.4
pre
Dependencies (3)
|
|
v2.0.0-rc.3
pre
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.3
pre
Dependencies (5)
|
|
v2.0.0-rc.2
pre
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.2
pre
Dependencies (5)
|
|
v2.0.0-rc.1
pre
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.1
pre
Dependencies (5)
|
|
v2.0.0-alpha
pre
5 CVEs
GO-2026-5884
GHSA-vh4v-2xq2-g5cg
Jul 24, 2026
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50151
GO-2026-5882
GHSA-jxpm-75mh-9fp7
Jul 24, 2026
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-48978
GO-2026-5885
GHSA-xf85-363p-868w
Jul 24, 2026
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go Fixed in
2.6.1
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2026-50163
GO-2026-5880
GHSA-fxhp-mv3v-67qp
Jul 24, 2026
Hardlink path traversal during tar extraction in oras.land/oras-go Hardlink path traversal during tar extraction in oras.land/oras-go Fixed in
2.6.2
References Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-50162
GO-2026-5879
GHSA-8xwf-rjm4-xvhv
Jul 24, 2026
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go Fixed in
2.6.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-alpha
pre
Dependencies (4)
|