credential forwarding via unvalidated Location header in oras-go blob upload
Upstream fixed versions: https://github.com/oras-project/oras-go: v2.6.2
details
- Finding IDs
- F-ORAS-LOCATION-UPLOAD-001
- CVE
- CVE-2026-50151
- GHSA
- GHSA-jxpm-75mh-9fp7
- Status
- patched
- CWE
- CWE-918
- Fixed in
- https://github.com/oras-project/oras-go: v2.6.2
- Recorded credit
- reporter: @1seal
- Note
- Public fix PR #1192; the published advisory lists v2.6.2 as patched. Reporter credit is retained in the upstream snapshot.
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- credential forwarding via unvalidated Location header in oras-go blob upload
- Upstream CWE
- CWE-918
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream fixed versions
- https://github.com/oras-project/oras-go: v2.6.2
- Upstream affected ranges
- https://github.com/oras-project/oras-go: v2.6.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-ORAS-LOCATION-UPLOAD-001: Outbound request trust. An unvalidated upload Location receives forwarded credentials. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-ORAS-LOCATION-UPLOAD-001
Security area (1seal assessment): Authorization. An unvalidated upload Location receives forwarded credentials. Reviewed 24 Sep 2026.