Bearer realm URL not validated, enabling SSRF to internal networks and TLS downgrade
Fixed in: oras-go v2.7.0
details
- Finding IDs
- F-ORAS-AUTH-001
- CVE
- CVE-2026-48978
- GHSA
- GHSA-xf85-363p-868w
- Status
- patched
- CWE
- CWE-319, CWE-918
- Fixed in
- oras-go v2.7.0
- Recorded credit
- @1seal credited as Analyst; advisory says reported by bugbunny.ai
- Note
- GHSA-xf85-363p-868w · Bearer realm URL not validated, enabling SSRF to internal networks and TLS downgrade. maps to local F-ORAS-AUTH-001; the public advisory credits @1seal as Analyst rather than reporter.
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Bearer realm URL not validated, enabling SSRF to internal networks and TLS downgrade
- Upstream CWE
- CWE-319, CWE-918
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: analyst (accepted)
F-ORAS-AUTH-001: Outbound request trust. Bearer realm URLs allow internal-network requests and TLS downgrade. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-ORAS-AUTH-001
Security area (1seal assessment): Authorization. Bearer realm URLs allow internal-network requests and TLS downgrade. Reviewed 24 Sep 2026.