CVE-2026-50163
Vulnerability Summary
Timeline
Description
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd_link") to resolve header.Linkname against the process current working directory for a Typeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link and Linkname="victim.secret" with io.deis.oras.content.unpack: "true", which can expose or tamper with files such as .env, .git/config, .aws/credentials, and ~/.ssh/config. This issue is fixed in version 2.6.2.
CVSS Metrics
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
EPSS Trends
Current EPSS score: 0.35%• Percentile: 28%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
- CWE-59•Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Affected Systems
- chainguard•argo-cd-3.0
all
- chainguard•argo-cd-3.0-compat
all
- chainguard•argo-cd-3.1
all
- chainguard•argo-cd-3.1-compat
all
- chainguard•argo-cd-3.2
< 3.2.12-r8
- chainguard•argo-cd-3.2-compat
< 3.2.12-r8
- chainguard•argo-cd-3.3
< 3.3.12-r7
- chainguard•argo-cd-3.3-compat
< 3.3.12-r7 | all
- chainguard•argo-cd-3.4
< 3.4.5-r2
- chainguard•argo-cd-3.4-compat
< 3.4.5-r2
- chainguard•argo-cd-fips-3.0
all
- chainguard•argo-cd-fips-3.0-compat
all
- chainguard•argo-cd-fips-3.1
all
- chainguard•argo-cd-fips-3.1-compat
all
- chainguard•argo-cd-fips-3.2
< 3.2.12-r15
- chainguard•argo-cd-fips-3.2-compat
< 3.2.12-r15
- chainguard•argo-cd-fips-3.3
< 3.3.12-r9
- chainguard•argo-cd-fips-3.3-compat
< 3.3.12-r9
- chainguard•argo-cd-fips-3.4
< 3.4.5-r3
- chainguard•argo-cd-fips-3.4-compat
< 3.4.5-r3
- chainguard•argocd-image-updater
< 1.3.0-r0
- chainguard•argocd-image-updater-fips
< 1.3.0-r0
- chainguard•cert-manager-cmctl
all
- chainguard•cert-manager-cmctl-fips
all
- chainguard•chaos-mesh
all
- chainguard•chaos-mesh-fips
all | < 2.8.4-r7
- chainguard•chartmuseum
< 0.16.6-r0
- chainguard•chartmuseum-fips
< 0.16.6-r0
- chainguard•cilium-cli
< 0.19.7-r1
- chainguard•cloudbeat-8.17
< 0
- chainguard•cloudbeat-8.19
< 8.19.20-r0
- chainguard•cloudbeat-9.0
< 0
- chainguard•cloudbeat-9.1
all
- chainguard•cloudbeat-9.2
all
- chainguard•cloudbeat-9.3
all
- chainguard•cloudbeat-9.4
< 9.4.5-r0
- chainguard•cloudbeat-9.5
< 0
- chainguard•cloudbeat-fips-8.17
< 0
- chainguard•cloudbeat-fips-8.19
< 8.19.20-r0
- chainguard•cloudbeat-fips-9.0
< 0
- chainguard•cloudbeat-fips-9.1
all
- chainguard•cloudbeat-fips-9.2
all
- chainguard•cloudbeat-fips-9.3
all | < 9.3.8-r11
- chainguard•cloudbeat-fips-9.4
< 9.4.5-r0
- chainguard•cloudbeat-fips-9.5
< 0
- chainguard•cluster-api-helm-controller
all | < 0.6.4-r20
- chainguard•cluster-api-helm-controller-fips
all
- chainguard•commercial-kyverno-1.13
all
- chainguard•commercial-kyverno-1.14
all
- chainguard•commercial-kyverno-1.15
all
Showing first 50 affected entries in server-rendered view.
References (11)
- https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp
- https://github.com/oras-project/oras-go/commit/b11f777f8d405c5023c4b307cfdc5068dfc3d406
- https://github.com/oras-project/oras-go
- https://github.com/oras-project/oras-go/pull/1232
- https://github.com/oras-project/oras-go/commit/c463c654ab3ef34422c1764cd619806cebf20451
- https://github.com/oras-project/oras-go/releases/tag/v2.6.2
- https://ubuntu.com/security/CVE-2026-50163
- https://www.cve.org/CVERecord?id=CVE-2026-50163
- https://security-tracker.debian.org/tracker/CVE-2026-50163
- https://nvd.nist.gov/vuln/detail/CVE-2026-50163
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50163.json