CVE-2026-50151
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.
Published:Jul 1, 2026
Last Modified:Aug 26, 2026
EPS:Jul 17, 2026
EPSS Score:0.00364
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Linuxfoundation
Product
Oras
Linuxfoundation
Oras
Vendor
Oras-project
Product
Oras-go
Oras-project
Oras-go
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
