Please follow the security policy to report a security vulnerability or concern.
Security: oras-project/oras-go
Security
SECURITY.md
-
Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)GHSA-m37j-52j7-pjw7 published
Aug 1, 2026 by TerryHoweHigh -
Blind SSRF via unvalidated Link header URL in pagination allows internal network probingGHSA-h7vf-4x9w-h99v published
Aug 1, 2026 by TerryHoweModerate -
ORAS Go forwards registry credentials across registry redirectsGHSA-vh4v-2xq2-g5cg published
Jun 11, 2026 by TerryHoweLow -
Bearer realm URL not validated, enabling SSRF to internal networks and TLS downgradeGHSA-xf85-363p-868w published
Jun 11, 2026 by TerryHoweModerate -
Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extractionGHSA-fxhp-mv3v-67qp published
Jun 11, 2026 by TerryHoweHigh -
file store write outside workingDir via symlink traversal in oras-goGHSA-8xwf-rjm4-xvhv published
Jun 11, 2026 by TerryHoweModerate -
credential forwarding via unvalidated Location header in oras-go blob uploadGHSA-jxpm-75mh-9fp7 published
Jun 11, 2026 by TerryHoweHigh
Learn more about advisories related to oras-project/oras-go in the GitHub Advisory Database