pkg:Debian/golang-oras-oras-go
4 total CVEsHIGH2
✅ Check your installed version
All known vulnerabilities
HIGH7.5CVE-2026-50151oras-go blob upload vulnerable to credential forwarding via unvalidated Location header from 0
HIGH7.1CVE-2026-50163`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution from 0
—CVE-2026-50162oras-go has file store write outside workingDir via symlink traversal from 0
—CVE-2026-48978oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens from 0