{"id":"GO-2026-6497","summary":"Blind SSRF via unvalidated Link header URL in pagination allows internal network probing in oras.land/oras-go","details":"Blind SSRF via unvalidated Link header URL in pagination allows internal network probing in oras.land/oras-go","aliases":["CVE-2026-85732","GHSA-h7vf-4x9w-h99v"],"modified":"2026-10-01T20:45:12.198173500Z","published":"2026-10-01T20:23:47Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6497"},"references":[{"type":"ADVISORY","url":"https://github.com/oras-project/oras-go/security/advisories/GHSA-h7vf-4x9w-h99v"},{"type":"WEB","url":"https://github.com/oras-project/oras-go/commit/31da1963f8c327dd089cd29faeae95cf0fc50842"},{"type":"WEB","url":"https://github.com/oras-project/oras-go/releases/tag/v2.6.2"}],"affected":[{"package":{"name":"oras.land/oras-go/v2","ecosystem":"Go","purl":"pkg:golang/oras.land/oras-go/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.6.2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6497.json"}}],"schema_version":"1.9.0"}