Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4351 articles · 196587 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-50151PATCHED
google · oras-go

oras-go: credential forwarding via unvalidated Location header in blob upload

Description

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.

Affected Products

VendorProductVersions
googleoras-go< 2.6.1

References

  • https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7(x_refsource_CONFIRM)
  • https://github.com/oras-project/oras-go/pull/1152(x_refsource_MISC)
  • https://github.com/oras-project/oras-go/commit/4683c46ef078091544f5f55fd25102f002806991(x_refsource_MISC)
  • https://github.com/oras-project/oras-go/releases/tag/v2.6.1(x_refsource_MISC)

Related News (2 articles)

Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier C
VulDB37d ago
CVE-2026-50151 | oras-project oras-go up to 2.6.0 BlobStore repository.go completePushAfterInitialPost improper authorization
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
oras.land/oras-go/v2@2.6.1
CWECWE-918
PublishedJul 1, 2026
Last enriched37d agov2
Tags
GHSA-jxpm-75mh-9fp7goCVE-2026-50151
Trending Score8
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76035
CVE-2026-76035: Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to ex
Trending: 32
HIGHCVE-2025-36940
CVE-2025-36940: Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U
Trending: 32
HIGHCVE-2026-76020
CVE-2026-76020: Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside
Trending: 31
HIGHCVE-2026-76017
CVE-2026-76017: Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary cod
Trending: 31
HIGHCVE-2026-76018
CVE-2026-76018: Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engin
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 1, 2026
Discovered by ZDM
Jul 1, 2026
Updated: tags
Jul 17, 2026
Patch Available
Jul 20, 2026

Version History

v2
Last enriched 37d ago
v2Tier C37d ago

Added CVE-2026-50151 identifier to tags

tags
via VulDB
v153d ago

Initial creation