PT-2026-93849 · Oras-Go · Oras-Go
CVE-2026-85732
·
Published
2026-09-16
·
Updated
2026-09-22
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
oras-go versions prior to 2.6.2
Description
The
parseLink() function in registry/remote/utils.go fails to validate the scheme, host, or port of absolute URLs provided in the Link response header from a registry. This allows a malicious registry to force a client to issue GET requests to arbitrary internal endpoints from the victim's network, resulting in blind server-side request forgery (SSRF). This issue affects pagination-based listing operations for Tags, Referrers, and Repositories. While the response body is not returned to the attacker, service reachability can be inferred through timing and error differences. Additionally, if the victim's credential store contains entries for the target host, those credentials may be attached to the request. The vulnerability is triggered when a victim performs a pagination-based listing operation against a malicious registry.Recommendations
Update oras-go to version 2.6.2 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oras-Go