CVE-2026-85732: oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing

Published Sep 16, 2026
·
Updated

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. Tags, Referrers, and Repositories pagination operations then issue a GET request to the attacker-selected URL from the victim's network, allowing blind server-side request forgery against internal services. The response body is not returned to the attacker, but timing and error differences can reveal service reachability, and credentials may be attached when the credential store has an entry for the target host. Exploitation requires a victim to perform a pagination-based listing operation against a malicious registry. The maintainer identifies this report as a duplicate of GHSA-3hr5-mjrr-hfjh and states that remediation is consolidated in that earlier advisory. The consolidated issue is fixed in version 2.6.2.

Affected Software

1 affected component
oras-go oras-go<2.6.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade oras-go to a version that resolves this vulnerability.

    Fixed in 2.6.2Patch GHSA-3hr5-mjrr-hfjh

Event History

Sep 16, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Applications using oras-go before 2.6.2 are exposed when they perform Tags, Referrers, or Repositories pagination against a malicious registry. The attacker does not need credentials or prior privileges, but must induce the victim application to run one of those listing operations.

2

What can an attacker learn or access through this issue?

The attacker can cause the victim to send GET requests to attacker-selected internal or external URLs, enabling blind probing of services reachable from the victim network. Response bodies are not returned, but timing and error differences can indicate reachability; credentials may also be attached if the credential store has an entry for the selected target host.

3

Are normal listing operations affected?

The affected behavior is specifically pagination-based listing for tags, referrers, and repositories, where a registry-controlled Link header supplies the next URL. A malicious registry can provide an absolute URL with an unvalidated scheme, host, or port.

4

What is the remediation?

Upgrade oras-go to version 2.6.2, which contains the consolidated fix. The maintainer identifies this report as a duplicate of GHSA-3hr5-mjrr-hfjh and states remediation is consolidated in that earlier advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203