Description
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. Tags, Referrers, and Repositories pagination operations then issue a GET request to the attacker-selected URL from the victim's network, allowing blind server-side request forgery against internal services. The response body is not returned to the attacker, but timing and error differences can reveal service reachability, and credentials may be attached when the credential store has an entry for the target host. Exploitation requires a victim to perform a pagination-based listing operation against a malicious registry. The maintainer identifies this report as a duplicate of GHSA-3hr5-mjrr-hfjh and states that remediation is consolidated in that earlier advisory. The consolidated issue is fixed in version 2.6.2.
Published: 2026-09-16
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Blind Server‑Side Request Forgery
Action: Patch
AI Analysis

Impact

oras-go is a Go library that allows retrieving OCI artifacts. A bug in its link‑parsing code causes the library to follow any absolute URL that appears in a Link response header, regardless of the scheme, host, or port. When a user performs a pagination request against a malicious registry, the library issues a blind GET request to an attacker‑chosen internal address. The response is not returned to the attacker, but differences in timing or error messages let the attacker deduce whether an internal service is reachable. Additionally, if the library's credential store contains authentication for the target host, those credentials are automatically attached to the forged request, potentially exposing sensitive secrets. This flaw permits internal network probing and credential leakage. The vulnerability is classified as Server‑Side Request Forgery (CWE‑918). The flaw is limited to cataloging and pagination operations that consume Link headers from registries. It does not provide direct code execution or data exfiltration from the victim machine, but it enables an attacker to discover and possibly interact with internal services. Because the flaw exists only in versions of oras-go before 2.6.2, any dependent application or service using those releases is affected. The vulnerability has a CVSS score of 4.7, indicating moderate severity. Exploitability is low with an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog, and a user must intentionally perform a pagination request via a compromised registry to trigger it. Affected Systems: "oras-go" library from oras‑project. The issue affects all releases older than version 2.6.2, including the actively used 2.6.1 and prior releases. Any application that uses oras-go to query an OCI registry, such as container build tools, linters, or artifact scanners, is at risk if it communicates with an attacker‑controlled registry. Risk and Exploitability: The CVSS score of 4.7 reflects the limited impact. The low EPSS score suggests that widespread exploitation is unlikely, but the attack requires only a malicious registry endpoint and a pagination request from the victim. An attacker can use internal timing side‑channels and attached credentials to map internal service topology and potentially retrieve sensitive data. Because credentials may be automatically sent, an attacker could access privileged services without knowing authentication details. Risk Assessment: While the risk is moderate and exploitation is non‑remote, the ability to probe internal services and leak credentials warrants timely remediation.

Affected Systems

The vulnerability impacts the oras‑project’s oras‑go library for all releases prior to 2.6.2. Any application or service that imports oras-go to perform OCI artifact management, especially those that query registries that the attacker can control, is exposed. The flaw arises during pagination operations that parse Link headers.

Risk and Exploitability

With a CVSS score of 4.7, the vulnerability is classified as moderate. The EPSS score of less than 1% indicates a low probability of immediate exploitation. The flaw is not present in the CISA KEV catalog. Attackers need to supply a malicious registry that provides a forged Link header; the victim must then initiate a pagination request. Exploitation reveals internal service reachability through timing differences and could send stored credentials to the target host.

Generated by OpenCVE AI on September 18, 2026 at 02:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade oras-go to version 2.6.2 or later to apply the fix that validates Link URLs.
  • Configure the registry client to restrict registry endpoints to trusted, internal registries only, preventing the library from contacting arbitrary hosts.
  • If immediate upgrade is not possible, limit or disable pagination requests in application logic until a secure version is deployed.

Generated by OpenCVE AI on September 18, 2026 at 02:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h7vf-4x9w-h99v oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
History

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Oras-project
Oras-project oras-go
Vendors & Products Oras-project
Oras-project oras-go

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. Tags, Referrers, and Repositories pagination operations then issue a GET request to the attacker-selected URL from the victim's network, allowing blind server-side request forgery against internal services. The response body is not returned to the attacker, but timing and error differences can reveal service reachability, and credentials may be attached when the credential store has an entry for the target host. Exploitation requires a victim to perform a pagination-based listing operation against a malicious registry. The maintainer identifies this report as a duplicate of GHSA-3hr5-mjrr-hfjh and states that remediation is consolidated in that earlier advisory. The consolidated issue is fixed in version 2.6.2.
Title oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

Oras-project Oras-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:29:51.661Z

Reserved: 2026-09-04T14:50:16.718Z

Link: CVE-2026-85732

cve-icon Vulnrichment

Updated: 2026-09-16T17:29:47.317Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T17:18:16.000

Modified: 2026-09-16T18:17:18.070

Link: CVE-2026-85732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)