Medium [CVE-2026-50151] Credential forwarding via unvalidated Location header during blob upload
This medium-severity Red Hat Linux advisory covers CVE-2026-50151 affecting Red Hat Advanced Cluster Management for Kubernetes 2.13, Gatekeeper 3, Multicluster Global Hub.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
oras-go is a Go library for managing OCI artifacts.
Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint.
This issue is fixed in version 2.6.1. A flaw was found in oras-go.
Additionally, it can enable client-side Server-Side Request Forgery (SSRF) to a cross-host target. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Weakness: CWE-522. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.13; Gatekeeper 3; Multicluster Global Hub; OpenShift Service Mesh 3; Red Hat Advanced Cluster Security 4; Red Hat OpenShift Container Platform 4; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Red Hat fixing advisory: RHSA-2026:47737.
- < 2.6.1
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
- 2.6.1
- rhacm2/multicloud-integrations-rhel9:1784652040
- rhacm2/multicluster-operators-channel-rhel9:1784741269
- rhacm2/multicluster-operators-subscription-rhel9:1784740143
- RHSA-2026:47737
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- Upgrade to oras-go v2.6.1 or later.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.