Browse all 4 CVE security advisories affecting oras-project. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-50151 | oras-go: credential forwarding via unvalidated Location header in blob upload — oras-goCWE-918 | 7.5 | High | 2026-07-17 |
| CVE-2026-50162 | oras-go: file store write outside workingDir via symlink traversal — oras-goCWE-73 | - | - | 2026-07-17 |
| CVE-2026-50163 | oras-go: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extraction — oras-goCWE-22 | 7.1 | High | 2026-07-17 |
| CVE-2026-48978 | oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens — oras-goCWE-918 | - | - | 2026-07-17 |
This page lists every published CVE security advisory associated with oras-project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.