Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-298f-872v-2rcx | ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph causes unbounded recursion and memory growth. This affects oras discover, whose recursive traversal is enabled by default because the --depth option defaults to 0 (unlimited), as well as the recursive referrer counting used by the oras backup and oras restore workflows. A cyclic graph can be as simple as A referring to B and B referring back to A. A malicious registry can use this to cause a client-side denial of service, exhausting CPU and memory and hanging automation or CI/CD pipelines that run ORAS against untrusted registry metadata. The vulnerability does not extend to code execution, artifact substitution, or integrity bypass. This issue has been fixed in version 1.3.3. | |
| Title | ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption | |
| Weaknesses | CWE-400 CWE-674 CWE-835 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-27T14:35:19.147Z
Reserved: 2026-06-16T23:18:03.169Z
Link: CVE-2026-55588
Updated: 2026-08-27T13:52:55.582Z
Status : Received
Published: 2026-08-25T21:17:02.350
Modified: 2026-08-27T17:18:49.220
Link: CVE-2026-55588
No data.
OpenCVE Enrichment
Updated: 2026-08-25T21:45:03Z
Github GHSA