CVE-2026-50163
Reported by GitHub_M · Published July 17, 2026
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd_link") to resolve header.Linkname against the process current working directory for a Typeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link and Linkname="victim.secret" with io.deis.oras.content.unpack: "true", which can expose or tamper with files such as .env, .git/config, .aws/credentials, and ~/.ssh/config. This issue is fixed in version 2.6.2.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| oras-project | oras-go | < 2.6.2 |
| wolfi | argocd-image-updater | 0, 0, 0 |
| chainguard | k8sgpt | *, *, * |
| chainguard | consul-k8s-fips-1.7 | *, *, * |
| wolfi | argo-cd-3.2 | 0, 0, 0 |
| wolfi | helm-push | *, *, * |
| chainguard | kargo-1.9 | *, *, * |
| chainguard | oras | 0, 0, 0 |
| chainguard | trivy-operator | 0 |
| chainguard | redpanda-operator | *, *, * |
| wolfi | zarf | 0, 0, 0 |
| chainguard | consul-k8s-1.7 | *, *, * |
| wolfi | cilium-cli | 0, 0, 0 |
| chainguard | envoy-gateway-fips-1.5 | *, *, * |
| chainguard | cilium-cli | 0, 0, 0 |
| wolfi | opa | 0, 0, 0 |
| chainguard | flux-helm-controller-fips | 0, 0 |
| wolfi | k8ssandra-client | 0, 0, 0 |
| chainguard | drone | 0, 0, 0 |
| chainguard | chartmuseum-fips | 0 |
…and 137 more
Timeline
- Jul 1, 2026 CVE Published
- Jul 2, 2026 Security Advisory
- Jul 18, 2026 EPSS Score
- Jul 23, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
References
- https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp x_refsource_CONFIRM
- https://github.com/oras-project/oras-go/pull/1232 x_refsource_MISC
- https://github.com/oras-project/oras-go/commit/c463c654ab3ef34422c1764cd619806cebf20451 x_refsource_MISC
- https://github.com/oras-project/oras-go/releases/tag/v2.6.2 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-50163 advisory
- https://github.com/oras-project/oras-go/commit/b11f777f8d405c5023c4b307cfdc5068dfc3d406 patch
- https://github.com/advisories/GHSA-fxhp-mv3v-67qp advisory