StackRadar

CVE-2026-50151

High

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
109
of 17,781 indexed, latest versions
Container images
105
deployed by those charts
Fix available
1 of 1
affected package

oras-go blob upload vulnerable to credential forwarding via unvalidated Location header

Carried by container images the latest versions of 109 of 17,781 indexed charts deploy, on 105 images.

Affected packageAffected versionsFixed inImages
oras.land/oras-go/v2golangv2.0.0, v2.0.2, v2.2.0, v2.3.0+4 more2.6.1105
OSV records
GHSA-jxpm-75mh-9fp7
Also known as
GO-2026-5882

Charts affected

109 by stars
ChartLatestAffected imagesRadar Score
orbitalryuunosukeds30.2.01 of 1See more

orbital ryuunosukeds3 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-50151.

Container imageDigestPackageFixed in
ryuunosukeds3/orbital:latest0879f7261b10
oras.land/oras-go/v2@v2.5.0
2.6.1

Open the chart page →

2,620
semaphoresemaphore-light1.0.01 of 1See more

semaphore semaphore-light 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-50151.

Container imageDigestPackageFixed in
semaphoreui/semaphore:latest3996804607eb
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,674
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-50151.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
oras.land/oras-go/v2@v2.3.0
2.6.1

Open the chart page →

2,314
orchestratremolo3.1.551 of 5See more

orchestra tremolo 3.1.55

1 of the 5 container images this version deploys carry CVE-2026-50151.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.42.0c9754bae1d79
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

7,637
trident-protecttrident-protect100.2606.01 of 2See more

trident-protect trident-protect 100.2606.0

1 of the 2 container images this version deploys carry CVE-2026-50151.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,331
trident-protect-consoletrident-protect100.2608.0-console1 of 3See more

trident-protect-console trident-protect 100.2608.0-console

1 of the 3 container images this version deploys carry CVE-2026-50151.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,322
vals-operatorvals-operatorVerified publisher0.8.11 of 1See more

vals-operator vals-operator 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-50151.

Container imageDigestPackageFixed in
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

696
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-50151.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,650
mesherywenerme1.0.691 of 1See more

meshery wenerme 1.0.69

1 of the 1 container images this version deploys carry CVE-2026-50151.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest9b68e81d392e
oras.land/oras-go/v2@v2.6.0
2.6.1

Open the chart page →

1,407

Container images carrying it

105 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/opsmxpublic/opa:1.12.084fb1af7401c
oras.land/oras-go/v2@v2.6.0
2.6.1
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
oras.land/oras-go/v2@v2.3.0
2.6.1
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
oras.land/oras-go/v2@v2.6.0
2.6.1
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
oras.land/oras-go/v2@v2.6.0
2.6.1
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
oras.land/oras-go/v2@v2.6.0
2.6.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.