LOWGo
GHSA-xf85-363p-868w· CVE-2026-48978, GO-2026-5885oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Modified: 9/10/2026
package
pkg:go/oras.land/oras-go
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Modified: 9/10/2026