Low [CVE-2026-48978] Information disclosure and TLS downgrade via malicious registry realm
This low-severity Red Hat Linux advisory covers CVE-2026-48978 affecting Gatekeeper 3, Multicluster Global Hub, OpenShift Service Mesh 3.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.
Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as,, and, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token.
This issue is fixed in version 2.6.1. A flaw was found in oras-go.
A remote attacker, operating a malicious registry or performing a man-in-the-middle attack, could exploit this to perform Server-Side Request Forgery (SSRF) against internal networks, potentially disclosing sensitive information.
Additionally, the flaw could lead to a Transport Layer Security (TLS) downgrade, causing user credentials to be sent over plaintext. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
Weakness: CWE-918. Affected Red Hat products: Gatekeeper 3; Multicluster Global Hub; OpenShift Service Mesh 3; Red Hat OpenShift Container Platform 4; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Red Hat does not currently list a fixing RHSA for this CVE.
- < 2.6.1
- < 169.254.169.254
- < 10.0.0.x
- < 127.0.0.1
- 10.0.0
Official advisory · high-confidence parse· fetched 3 days ago·verify at source
Mitigation checklist
- Upgrade to oras-go v2.6.1 or later.
Official advisory · high-confidence parse· fetched 3 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.