VDB
CVE-2026-50151
CVE-2026-50151
PUBLISHED
CVSS 7.5 HIGH
Reported by GitHub_M · Published July 17, 2026
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| oras-project | oras-go | < 2.6.1 |
| wolfi | tigera-operator-1.41 | 0, 0, 0 |
| wolfi | maru | 0, 0, 0 |
| chainguard | rancher-2.11 | 0, 0, 0 |
| chainguard | cert-manager-cmctl-fips | 0, 0, 0 |
| chainguard | cloudbeat-fips-9.1 | 0, 0, 0 |
| chainguard | headlamp-fips | 0, 0, 0 |
| chainguard | chaos-mesh-fips | 0, 0, 0 |
| wolfi | consul-k8s-1.9 | 0, 0, 0 |
| chainguard | teleport-18 | 0, 0 |
| wolfi | headlamp | 0, 0, 0 |
| chainguard | rancher-agent-2.14 | 0, 0, 0 |
| chainguard | kube-arangodb-1.4 | 0, 0, 0 |
| wolfi | linkerd2 | 0, 0, 0 |
| chainguard | crossplane-2.3 | 0, 0, 0 |
| chainguard | chaos-mesh | 0, 0, 0 |
| wolfi | rancher-helm-3 | 0, 0, 0 |
| chainguard | tigera-operator-fips-1.42 | 0, 0 |
| chainguard | consul-k8s-1.7 | 0, 0, 0 |
| chainguard | argo-cd-3.3 | 0, 0, 0 |
…and 194 more
Timeline
- Jul 1, 2026 CVE Published
- Jul 2, 2026 Security Advisory
- Jul 18, 2026 EPSS Score
- Jul 20, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
References
- https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7 x_refsource_CONFIRM
- https://github.com/oras-project/oras-go/pull/1152 x_refsource_MISC
- https://github.com/oras-project/oras-go/commit/4683c46ef078091544f5f55fd25102f002806991 x_refsource_MISC
- https://github.com/oras-project/oras-go/releases/tag/v2.6.1 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-50151 advisory
- https://github.com/advisories/GHSA-jxpm-75mh-9fp7 advisory