StackRadar

CVE-2026-48978

Low

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.1
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
213
of 17,781 indexed, latest versions
Container images
216
deployed by those charts
Fix available
1 of 2
affected packages

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

Carried by container images the latest versions of 213 of 17,781 indexed charts deploy, on 216 images.

Affected packageAffected versionsFixed inImages
oras.land/oras-gogolangv0.4.0, v1.1.0, v1.1.1, v1.2.0+6 moreno fix listed125
oras.land/oras-go/v2golangv2.0.0, v2.0.2, v2.2.0, v2.3.0+4 more2.6.1105
OSV records
GHSA-xf85-363p-868w
Also known as
GO-2026-5885

Charts affected

213 by stars
ChartLatestAffected imagesRadar Score
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
oras.land/oras-go/v2@v2.3.0
2.6.1

Open the chart page →

2,314
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
oras.land/oras-go@v1.2.3
no fix listed

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
oras.land/oras-go@v1.2.4-0.20230801060855-932dd06d38af
no fix listed

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
oras.land/oras-go@v1.1.0
no fix listed

Open the chart page →

30,687
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
oras.land/oras-go@v1.2.4
no fix listed

Open the chart page →

1,360
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.42.0c9754bae1d79
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

7,637
trident-protecttrident-protect100.2606.01 of 2See more

trident-protect trident-protect 100.2606.0

1 of the 2 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,331
trident-protect-consoletrident-protect100.2608.0-console1 of 3See more

trident-protect-console trident-protect 100.2608.0-console

1 of the 3 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,322
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
oras.land/oras-go@v1.2.5
no fix listed

Open the chart page →

2,477
vals-operatorvals-operatorVerified publisher0.8.11 of 1See more

vals-operator vals-operator 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

696
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,650
mesherywenerme1.0.691 of 1See more

meshery wenerme 1.0.69

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest9b68e81d392e
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,407
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
oras.land/oras-go@v1.2.2
no fix listed

Open the chart page →

13,677

Container images carrying it

216 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
oras.land/oras-go@v1.2.2
no fix listed
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
oras.land/oras-go/v2@v2.2.0
2.6.1
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
oras.land/oras-go@v1.2.4
no fix listed
1
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
oras.land/oras-go/v2@v2.6.0
2.6.1
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
oras.land/oras-go@v1.2.2
no fix listed
1
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
oras.land/oras-go@v1.2.4
no fix listed
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
oras.land/oras-go@v0.4.0
no fix listed
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
oras.land/oras-go/v2@v2.6.0
2.6.1
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
oras.land/oras-go/v2@v2.6.0
2.6.1
1
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
oras.land/oras-go/v2@v2.6.0
2.6.1
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
oras.land/oras-go@v1.1.1
oras.land/oras-go/v2@v2.3.0
no fix listed
2.6.1
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
oras.land/oras-go@v1.2.4
no fix listed
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
oras.land/oras-go@v0.4.0
no fix listed
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
oras.land/oras-go/v2@v2.6.0
2.6.1
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
oras.land/oras-go/v2@v2.6.0
2.6.1
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
oras.land/oras-go/v2@v2.6.0
2.6.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.