Skip to content
VulniPulse
Medium5.9Red Hat Linux

Medium [CVE-2026-50151] Credential forwarding via unvalidated Location header during blob upload

This medium-severity Red Hat Linux advisory covers CVE-2026-50151 affecting Red Hat Advanced Cluster Management for Kubernetes 2.13, Gatekeeper 3, Multicluster Global Hub.

CVE-2026-50151 Published Jul 1, 2026Updated by vendor Jul 1, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

oras-go is a Go library for managing OCI artifacts.

Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint.

This issue is fixed in version 2.6.1. A flaw was found in oras-go.

Additionally, it can enable client-side Server-Side Request Forgery (SSRF) to a cross-host target. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

Weakness: CWE-522. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.13; Gatekeeper 3; Multicluster Global Hub; OpenShift Service Mesh 3; Red Hat Advanced Cluster Security 4; Red Hat OpenShift Container Platform 4; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

Red Hat fixing advisory: RHSA-2026:47737.

Affected versions
  • < 2.6.1

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • 2.6.1
  • rhacm2/multicloud-integrations-rhel9:1784652040
  • rhacm2/multicluster-operators-channel-rhel9:1784741269
  • rhacm2/multicluster-operators-subscription-rhel9:1784740143
  • RHSA-2026:47737

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade to oras-go v2.6.1 or later.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.