Impact
oras-go is a Go library that allows retrieving OCI artifacts. A bug in its link‑parsing code causes the library to follow any absolute URL that appears in a Link response header, regardless of the scheme, host, or port. When a user performs a pagination request against a malicious registry, the library issues a blind GET request to an attacker‑chosen internal address. The response is not returned to the attacker, but differences in timing or error messages let the attacker deduce whether an internal service is reachable. Additionally, if the library's credential store contains authentication for the target host, those credentials are automatically attached to the forged request, potentially exposing sensitive secrets. This flaw permits internal network probing and credential leakage. The vulnerability is classified as Server‑Side Request Forgery (CWE‑918). The flaw is limited to cataloging and pagination operations that consume Link headers from registries. It does not provide direct code execution or data exfiltration from the victim machine, but it enables an attacker to discover and possibly interact with internal services. Because the flaw exists only in versions of oras-go before 2.6.2, any dependent application or service using those releases is affected. The vulnerability has a CVSS score of 4.7, indicating moderate severity. Exploitability is low with an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog, and a user must intentionally perform a pagination request via a compromised registry to trigger it. Affected Systems: "oras-go" library from oras‑project. The issue affects all releases older than version 2.6.2, including the actively used 2.6.1 and prior releases. Any application that uses oras-go to query an OCI registry, such as container build tools, linters, or artifact scanners, is at risk if it communicates with an attacker‑controlled registry. Risk and Exploitability: The CVSS score of 4.7 reflects the limited impact. The low EPSS score suggests that widespread exploitation is unlikely, but the attack requires only a malicious registry endpoint and a pagination request from the victim. An attacker can use internal timing side‑channels and attached credentials to map internal service topology and potentially retrieve sensitive data. Because credentials may be automatically sent, an attacker could access privileged services without knowing authentication details. Risk Assessment: While the risk is moderate and exploitation is non‑remote, the ability to probe internal services and leak credentials warrants timely remediation.
Affected Systems
The vulnerability impacts the oras‑project’s oras‑go library for all releases prior to 2.6.2. Any application or service that imports oras-go to perform OCI artifact management, especially those that query registries that the attacker can control, is exposed. The flaw arises during pagination operations that parse Link headers.
Risk and Exploitability
With a CVSS score of 4.7, the vulnerability is classified as moderate. The EPSS score of less than 1% indicates a low probability of immediate exploitation. The flaw is not present in the CISA KEV catalog. Attackers need to supply a malicious registry that provides a forged Link header; the victim must then initiate a pagination request. Exploitation reveals internal service reachability through timing differences and could send stored credentials to the target host.
OpenCVE Enrichment
Github GHSA