Skip to content
VulniPulse
Low3.1Red Hat Linux

Low [CVE-2026-48978] Information disclosure and TLS downgrade via malicious registry realm

This low-severity Red Hat Linux advisory covers CVE-2026-48978 affecting Gatekeeper 3, Multicluster Global Hub, OpenShift Service Mesh 3.

CVE-2026-48978 Published Jul 1, 2026Updated by vendor Jul 1, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.

Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as,, and, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token.

This issue is fixed in version 2.6.1. A flaw was found in oras-go.

A remote attacker, operating a malicious registry or performing a man-in-the-middle attack, could exploit this to perform Server-Side Request Forgery (SSRF) against internal networks, potentially disclosing sensitive information.

Additionally, the flaw could lead to a Transport Layer Security (TLS) downgrade, causing user credentials to be sent over plaintext. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).

Weakness: CWE-918. Affected Red Hat products: Gatekeeper 3; Multicluster Global Hub; OpenShift Service Mesh 3; Red Hat OpenShift Container Platform 4; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

Red Hat does not currently list a fixing RHSA for this CVE.

Affected versions
  • < 2.6.1
  • < 169.254.169.254
  • < 10.0.0.x
  • < 127.0.0.1
  • 10.0.0

Official advisory · high-confidence parse· fetched 3 days ago·verify at source

Fixed versions
  • 2.6.1

Official advisory · high-confidence parse· fetched 3 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade to oras-go v2.6.1 or later.

Official advisory · high-confidence parse· fetched 3 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.