Oras-project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    1
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-48978

    oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

    Last Modified: Jul 27, 2026
    Published: Jul 01, 2026

    CVE-2026-50162

    oras-go: file store write outside workingDir via symlink traversal

    Last Modified: Jul 27, 2026
    Published: Jul 01, 2026

    CVE-2026-50163

    oras-go: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extraction

    Last Modified: Jul 27, 2026
    Published: Jul 01, 2026

    CVE-2026-50151

    oras-go: credential forwarding via unvalidated Location header in blob upload

    Last Modified: Aug 26, 2026
    Published: Jul 01, 2026
    Items Per Page
    Oras-Project Vulnerabilities & Security CVEs | CVE-DB