12 Total advisories
12 Vulnerabilities
0 Malware
Dependency scanning
Check whether oras.land/oras-go/v2 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 4.7
CVE-2026-85732
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
HIGH 8.8
CVE-2026-85731
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
UNKNOWN
GO-2026-5884
ORAS Go forwards registry credentials across registry redirects
UNKNOWN
CVE-2026-50162
oras-go has file store write outside workingDir via symlink traversal
UNKNOWN
CVE-2026-48978
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
HIGH 7.5
CVE-2026-50151
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
HIGH 7.1
CVE-2026-50163
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
UNKNOWN
CVE-2026-48978
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go
UNKNOWN
CVE-2026-50163
Hardlink path traversal during tar extraction in oras.land/oras-go
UNKNOWN
GHSA-vh4v-2xq2-g5cg
ORAS Go forwards registry credentials across registry redirects in oras.land/oras-go
UNKNOWN
CVE-2026-50151
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go
UNKNOWN
CVE-2026-50162
Oras-go: File store write outside workingDir via symlink traversal in oras.land/oras-go
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes