VDB
CVE-2026-48978
CVE-2026-48978
PUBLISHED
CVSS 2.0999999046325684 LOW
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
EPSS 0.21% · 11.4th percentile
Risk Scores
CVSS 4.0
2.0999999046325684
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.21%
11.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | helm-push | 0, 0, 0 |
| chainguard | argo-cd-fips-3.2 | 0, 0, 0 |
| chainguard | gitlab-operator-fips | 0, 0, 0 |
| wolfi | kyverno-1.16 | 0, 0, 0 |
| chainguard | cert-manager-cmctl-fips | 0, 0, 0 |
| chainguard | k8ssandra-client | 0, 0, 0 |
| chainguard | rancher-helm-3 | 0, 0, 0 |
| wolfi | tigera-operator-1.42 | 0, 0, 0 |
| chainguard | opentofu-1.11 | 0, 0, 0 |
| wolfi | manifest-tool | 0, 0, 0 |
| chainguard | redpanda-operator-26.1 | 0, 0, 0 |
| chainguard | cloudbeat-9.0 | 0, 0, 0 |
| chainguard | headlamp | 0, 0, 0 |
| wolfi | vcluster | 0, 0, 0 |
| chainguard | chaos-mesh-fips | 0, 0, 0 |
| chainguard | gitness | 0, 0, 0 |
| wolfi | zarf | 0, 0, 0 |
| chainguard | k9s-fips | 0, 0, 0 |
| chainguard | cloudbeat-fips-9.0 | 0, 0, 0 |
| wolfi | linkerd2 | 0, 0, 0 |
…and 202 more
Timeline
- Jul 1, 2026 CVE Published
- Jul 5, 2026 Security Advisory
- Jul 18, 2026 EPSS Score
- Jul 23, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-48978 advisory
- https://github.com/advisories/GHSA-xf85-363p-868w advisory
- https://github.com/oras-project/oras-go/security/advisories/GHSA-xf85-363p-868w url
- https://github.com/oras-project/oras-go/commit/7a9f4b0b9558821b0422152ebe21ae56930fe764 patch
- https://github.com/oras-project/oras-go/releases/tag/v2.6.1 url