Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48978

Опубликовано: 01 июл. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.

A flaw was found in oras-go. The auth.Client in oras-go does not properly validate the scheme or host of the realm URL provided in a registry's WWW-Authenticate: Bearer challenge. A remote attacker, operating a malicious registry or performing a man-in-the-middle attack, could exploit this to perform Server-Side Request Forgery (SSRF) against internal networks, potentially disclosing sensitive information. Additionally, the flaw could lead to a Transport Layer Security (TLS) downgrade, causing user credentials to be sent over plaintext.

Отчет

A flaw was found in oras-go. The auth.Client follows the realm URL from a registry's Bearer challenge without validating scheme or host, enabling SSRF to internal networks and TLS downgrade attacks.

Меры по смягчению последствий

Upgrade to oras-go v2.6.1 or later.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/istio-rhel9-operatorFix deferred
Red Hat OpenShift Container Platform 4openshift4/cnf-tests-rhel8Fix deferred
Red Hat OpenShift Container Platform 4openshift4/metallb-rhel8-operatorFix deferred
Red Hat OpenShift Container Platform 4openshift4/metallb-rhel9-operatorFix deferred
Red Hat OpenShift Container Platform 4openshift4/oc-mirror-plugin-rhel8Fix deferred
Red Hat OpenShift Container Platform 4openshift4/oc-mirror-plugin-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-ansible-operatorFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-azure-cluster-api-controllers-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2499689oras-go: oras-go: Information disclosure and TLS downgrade via malicious registry realm

EPSS

Процентиль: 11%
0.00211
Низкий

3.1 Low

CVSS3

Связанные уязвимости

ubuntu
18 дней назад

(oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...)

nvd
20 дней назад

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.

debian
20 дней назад

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...

suse-cvrf
24 дня назад

Security update for helm

github
около 1 месяца назад

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

EPSS

Процентиль: 11%
0.00211
Низкий

3.1 Low

CVSS3