Threats Tagged 'cve-2026-85732'
View all threats tagged with 'cve-2026-85732'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-85732'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-85732 is a server-side request forgery (SSRF) vulnerability in the oras-go Go library used for managing OCI artifacts. Versions prior to 2.6.2 improperly validate absolute URLs from a registry-controlled Link response header, allowing an attacker to induce the victim to send GET requests to attacker-chosen URLs within the victim's network. The vulnerability affects pagination operations such as Tags, Referrers, and Repositories. While the response body is not exposed to the attacker, timing and error differences can reveal internal service reachability, and credentials may be sent if stored for the target host. Exploitation requires the victim to perform a pagination listing against a malicious registry. The issue is fixed in version 2.6.2. Join the discussion | CVE Database V5 | 09/16/2026, 16:22:14 UTC Added: 09/16/2026, 17:47:12 UTC |
Showing 1 to 1 of 1 result