Bug 2499694 (CVE-2026-50162)

Summary: CVE-2026-50162 oras-go: oras-go: File store write outside working directory via symlink traversal
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abarbaro, akhatavk, akoudelk, alizardo, amctagga, anjoseph, anpicker, aoconnor, aos-team-art-private, aprice, asdas, bniver, dbosanac, dfreiber, dkeler, dpaolell, drow, eborisov, eglynn, flucifre, gbenhaim, gmeno, gparvin, groman, hasun, jburrell, jchui, jdelft, jfula, jhe, jjoyce, jowilson, jprabhak, jpretori, jreimann, jsamir, jschluet, jupierce, kbempah, ktsao, lball, lbragsta, lgamliel, lgarciaa, lhh, manissin, mbenjamin, mbiarnes, mburns, mdessi, mgarciac, mhackett, mrizzi, nboldt, ngough, niyer, nyancey, oaljalju, oezr, ometelka, pcattana, ppalepu, ppostler, prdhamdh, psrna, ptisnovs, rhaigner, sbratsla, sghai, sidsharm, solenoci, sostapov, suppawar, syedriko, thason, twaugh, vereddy, veshanka, vkumar, vlaad, wenshen, wtam, xdharmai
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob title, could exploit this vulnerability to create files outside the intended working directory. This filesystem boundary bypass allows for arbitrary file creation, potentially leading to unauthorized data modification or system compromise depending on the runtime environment.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-13 14:40:59 UTC
The file content store in oras-go attempts to confine writes to workingDir when AllowPathTraversalOnWrite=false, but the guard is lexical and does not account for symlink traversal. If workingDir contains a symlink path component and an attacker-controlled blob title targets a path under that symlink, pushFile() can create a file outside workingDir, violating the intended confinement guarantee. Fixed in oras-go v2.6.1.