VDB

CVE-2026-48978

CVE-2026-48978 PUBLISHED CVSS 2.0999999046325684 LOW

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

EPSS 0.21% · 11.4th percentile

Risk Scores

CVSS 4.0
2.0999999046325684
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.21%
11.4th percentile

Affected Products

VendorProductVersions
chainguardhelm-push0, 0, 0
chainguardargo-cd-fips-3.20, 0, 0
chainguardgitlab-operator-fips0, 0, 0
wolfikyverno-1.160, 0, 0
chainguardcert-manager-cmctl-fips0, 0, 0
chainguardk8ssandra-client0, 0, 0
chainguardrancher-helm-30, 0, 0
wolfitigera-operator-1.420, 0, 0
chainguardopentofu-1.110, 0, 0
wolfimanifest-tool0, 0, 0
chainguardredpanda-operator-26.10, 0, 0
chainguardcloudbeat-9.00, 0, 0
chainguardheadlamp0, 0, 0
wolfivcluster0, 0, 0
chainguardchaos-mesh-fips0, 0, 0
chainguardgitness0, 0, 0
wolfizarf0, 0, 0
chainguardk9s-fips0, 0, 0
chainguardcloudbeat-fips-9.00, 0, 0
wolfilinkerd20, 0, 0

…and 202 more

Timeline

  • Jul 1, 2026 CVE Published
  • Jul 5, 2026 Security Advisory
  • Jul 18, 2026 EPSS Score
  • Jul 23, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›