VDB

CVE-2026-50151

CVE-2026-50151 PUBLISHED CVSS 7.5 HIGH

Reported by GitHub_M · Published July 17, 2026

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
oras-projectoras-go< 2.6.1
wolfitigera-operator-1.410, 0, 0
wolfimaru0, 0, 0
chainguardrancher-2.110, 0, 0
chainguardcert-manager-cmctl-fips0, 0, 0
chainguardcloudbeat-fips-9.10, 0, 0
chainguardheadlamp-fips0, 0, 0
chainguardchaos-mesh-fips0, 0, 0
wolficonsul-k8s-1.90, 0, 0
chainguardteleport-180, 0
wolfiheadlamp0, 0, 0
chainguardrancher-agent-2.140, 0, 0
chainguardkube-arangodb-1.40, 0, 0
wolfilinkerd20, 0, 0
chainguardcrossplane-2.30, 0, 0
chainguardchaos-mesh0, 0, 0
wolfirancher-helm-30, 0, 0
chainguardtigera-operator-fips-1.420, 0
chainguardconsul-k8s-1.70, 0, 0
chainguardargo-cd-3.30, 0, 0

…and 194 more

Timeline

  • Jul 1, 2026 CVE Published
  • Jul 2, 2026 Security Advisory
  • Jul 18, 2026 EPSS Score
  • Jul 20, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›