Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50151

Опубликовано: 01 июл. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.

A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attacker-controlled endpoint to receive the caller's credentials, leading to information disclosure. Additionally, it can enable client-side Server-Side Request Forgery (SSRF) to a cross-host target.

Отчет

A flaw was found in oras-go. During monolithic blob upload, the Authorization header is reused for cross-host Location redirects, allowing a malicious registry to exfiltrate caller credentials.

Меры по смягчению последствий

Upgrade to oras-go v2.6.1 or later.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Gatekeeper 3gatekeeper/gatekeeper-rhel9Under investigation
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Under investigation
OpenShift Service Mesh 3openshift-service-mesh/istio-rhel9-operatorUnder investigation
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel9Affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-rhel9-operatorAffected
Red Hat OpenShift Container Platform 4openshift4/cnf-tests-rhel8Under investigation
Red Hat OpenShift Container Platform 4openshift4/metallb-rhel8-operatorUnder investigation
Red Hat OpenShift Container Platform 4openshift4/metallb-rhel9-operatorUnder investigation
Red Hat OpenShift Container Platform 4openshift4/oc-mirror-plugin-rhel8Under investigation
Red Hat OpenShift Container Platform 4openshift4/oc-mirror-plugin-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=2499693oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload

EPSS

Процентиль: 29%
0.00364
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
20 дней назад

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.

CVSS3: 7.5
nvd
20 дней назад

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.

CVSS3: 7.5
debian
20 дней назад

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...

CVSS3: 7.5
github
около 1 месяца назад

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

suse-cvrf
17 дней назад

Security update for trivy

EPSS

Процентиль: 29%
0.00364
Низкий

5.9 Medium

CVSS3