StackRadar

CVE-2026-48978

Low

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.1
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
213
of 17,781 indexed, latest versions
Container images
216
deployed by those charts
Fix available
1 of 2
affected packages

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

Carried by container images the latest versions of 213 of 17,781 indexed charts deploy, on 216 images.

Affected packageAffected versionsFixed inImages
oras.land/oras-gogolangv0.4.0, v1.1.0, v1.1.1, v1.2.0+6 moreno fix listed125
oras.land/oras-go/v2golangv2.0.0, v2.0.2, v2.2.0, v2.3.0+4 more2.6.1105
OSV records
GHSA-xf85-363p-868w
Also known as
GO-2026-5885

Charts affected

213 by stars
ChartLatestAffected imagesRadar Score
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
oras.land/oras-go/v2@v2.3.0
2.6.1

Open the chart page →

2,314
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
oras.land/oras-go@v1.2.3
no fix listed

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
oras.land/oras-go@v1.2.4-0.20230801060855-932dd06d38af
no fix listed

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
oras.land/oras-go@v1.1.0
no fix listed

Open the chart page →

30,687
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
oras.land/oras-go@v1.2.4
no fix listed

Open the chart page →

1,360
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.42.0c9754bae1d79
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

7,637
trident-protecttrident-protect100.2606.01 of 2See more

trident-protect trident-protect 100.2606.0

1 of the 2 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,331
trident-protect-consoletrident-protect100.2608.0-console1 of 3See more

trident-protect-console trident-protect 100.2608.0-console

1 of the 3 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,322
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
oras.land/oras-go@v1.2.5
no fix listed

Open the chart page →

2,477
vals-operatorvals-operatorVerified publisher0.8.11 of 1See more

vals-operator vals-operator 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

696
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,650
mesherywenerme1.0.691 of 1See more

meshery wenerme 1.0.69

1 of the 1 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest9b68e81d392e
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,407
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-48978.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
oras.land/oras-go@v1.2.2
no fix listed

Open the chart page →

13,677

Container images carrying it

216 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
oras.land/oras-go/v2@v2.6.0
2.6.1
7
quay.io/devtron/kubectl:latest2ad610626658
oras.land/oras-go@v1.2.0
no fix listed
6
keelhq/keel:latest73714afb4443
oras.land/oras-go@v1.2.5
no fix listed
5
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
oras.land/oras-go@v1.2.2
no fix listed
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
oras.land/oras-go@v1.2.3
no fix listed
4
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
oras.land/oras-go/v2@v2.6.0
2.6.1
3
quay.io/devtron/ai-agent:0.0.16545dac92173
oras.land/oras-go@v1.2.5
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
oras.land/oras-go@v1.2.0
no fix listed
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
oras.land/oras-go/v2@v2.6.0
2.6.1
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
oras.land/oras-go/v2@v2.6.0
2.6.1
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
oras.land/oras-go/v2@v2.6.0
2.6.1
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
oras.land/oras-go/v2@v2.6.0
2.6.1
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
oras.land/oras-go@v1.2.4-0.20230801060855-932dd06d38af
no fix listed
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
oras.land/oras-go/v2@v2.6.0
2.6.1
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
oras.land/oras-go/v2@v2.6.0
2.6.1
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
oras.land/oras-go/v2@v2.6.0
2.6.1
3
alpine/k8s:1.32.12048f8d9c8cc7
oras.land/oras-go/v2@v2.6.0
2.6.1
2
dtzar/helm-kubectl:3.14.455429449408e
oras.land/oras-go@v1.2.4
no fix listed
2
ilum/api:6.7.3624fd09528c8
oras.land/oras-go@v1.2.5
no fix listed
2
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
oras.land/oras-go@v1.2.0
no fix listed
2
meshery/meshery:stable-latest9b68e81d392e
oras.land/oras-go/v2@v2.6.0
2.6.1
2
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
oras.land/oras-go/v2@v2.6.0
2.6.1
2
ghcr.io/appscode/fargocd:v0.0.31f5c791fc54d
oras.land/oras-go/v2@v2.6.0
2.6.1
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
oras.land/oras-go/v2@v2.5.0
2.6.1
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
oras.land/oras-go@v1.2.5
oras.land/oras-go/v2@v2.5.0
no fix listed
2.6.1
2
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
oras.land/oras-go@v1.2.0
no fix listed
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
oras.land/oras-go/v2@v2.6.0
2.6.1
2
alpine/helm105741fa6621
oras.land/oras-go@v1.2.5
no fix listed
1
alpine/helm:4.1.0905a068da431
oras.land/oras-go/v2@v2.6.0
2.6.1
1
alpine/k8s:1.22.600ac10bcb759
oras.land/oras-go@v0.4.0
no fix listed
1
alpine/k8s:1.27.321b24e6bf801
oras.land/oras-go@v1.2.2
no fix listed
1
alpine/k8s:1.36.244ef4942e171
oras.land/oras-go/v2@v2.6.0
2.6.1
1
alpine/k8s:1.31.106dbe6f391eda
oras.land/oras-go@v1.2.6
oras.land/oras-go/v2@v2.5.0
no fix listed
2.6.1
1
alpine/k8s:1.31.137a319b15cfc9
oras.land/oras-go@v1.2.6
oras.land/oras-go/v2@v2.6.0
no fix listed
2.6.1
1
alpine/k8s:1.32.47e1e7d5b7a96
oras.land/oras-go@v1.2.6
no fix listed
1
alpine/k8s:1.31.49c4976d47656
oras.land/oras-go@v1.2.5
no fix listed
1
alpine/k8s:1.35.6b7a12c5ddf26
oras.land/oras-go/v2@v2.6.0
2.6.1
1
alpine/k8s:1.30.0bd01dae02676
oras.land/oras-go@v1.2.4
no fix listed
1
alpine/k8s:1.30.2cd560fce90f7
oras.land/oras-go@v1.2.4
no fix listed
1
alpine/k8s:1.35.5d870622d0040
oras.land/oras-go/v2@v2.6.0
2.6.1
1
alpine/k8s:1.28.13e5c0b053fed7
oras.land/oras-go@v1.2.2
no fix listed
1
alpine/k8s:1.32.3eec354133193
oras.land/oras-go@v1.2.5
no fix listed
1
alpine/k8s:1.28.2fc059f056ad0
oras.land/oras-go@v1.2.3
no fix listed
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
oras.land/oras-go@v1.2.5
oras.land/oras-go/v2@v2.6.0
no fix listed
2.6.1
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
oras.land/oras-go@v1.2.5
no fix listed
1
aquasec/trivy:0.43.1944a04445179
oras.land/oras-go@v1.2.3
no fix listed
1
aquasec/trivy:0.32.0973d0df16189
oras.land/oras-go@v1.1.1
no fix listed
1
aquasec/trivy:0.69.3bcc376de8d77
oras.land/oras-go/v2@v2.6.0
2.6.1
1
artifacthub/hub:v1.19.0111918d8c399
oras.land/oras-go@v1.2.5
no fix listed
1
artifacthub/scanner:v1.23.02d8365601f0e
oras.land/oras-go/v2@v2.6.0
2.6.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.