—
GO-2026-5882
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go
Quick fix
GO-2026-5882 — oras.land/oras-go/v2: upgrade to the fixed version with the command below.
go get oras.land/oras-go/v2@v2.6.1 Details
Oras-go: Blob upload vulnerable to credential forwarding via unvalidated Location header in oras.land/oras-go
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7 [ADVISORY]
- https://github.com/oras-project/oras-go/commit/4683c46ef078091544f5f55fd25102f002806991 [FIX]
- https://github.com/oras-project/oras-go/pull/1152 [FIX]
- https://github.com/oras-project/oras-go/releases/tag/v2.6.1 [WEB]