VDB
KO

GO-2026-5885

Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go

Quick fix

GO-2026-5885 — oras.land/oras-go/v2: upgrade to the fixed version with the command below.

go get oras.land/oras-go/v2@v2.6.1

Details

Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / oras.land/oras-go/v2
Introduced in: 0 Fixed in: 2.6.1
Fix go get oras.land/oras-go/v2@v2.6.1

References