PT-2026-93849 · Oras-Go · Oras-Go

CVE-2026-85732

·

Published

2026-09-16

·

Updated

2026-09-22

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions oras-go versions prior to 2.6.2
Description The parseLink() function in registry/remote/utils.go fails to validate the scheme, host, or port of absolute URLs provided in the Link response header from a registry. This allows a malicious registry to force a client to issue GET requests to arbitrary internal endpoints from the victim's network, resulting in blind server-side request forgery (SSRF). This issue affects pagination-based listing operations for Tags, Referrers, and Repositories. While the response body is not returned to the attacker, service reachability can be inferred through timing and error differences. Additionally, if the victim's credential store contains entries for the target host, those credentials may be attached to the request. The vulnerability is triggered when a victim performs a pagination-based listing operation against a malicious registry.
Recommendations Update oras-go to version 2.6.2 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85732
GHSA-H7VF-4X9W-H99V
OPENSUSE-SU-2026:11832-1
OPENSUSE-SU-2026:11848-1

Affected Products

Oras-Go