SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-55588

MEDIUM · CVSS 6.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The ORAS CLI versions up to 1.3.2 are vulnerable to a denial of service due to unbounded recursion caused by cyclic referrer graphs from malicious OCI registries. This can lead to excessive CPU and memory consumption, potentially disrupting automation and CI/CD pipelines that rely on ORAS for managing artifacts. Organizations using ORAS for artifact management should prioritize upgrading to version 1.3.3 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55588
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph causes unbounded recursion and memory growth. This affects oras discover, whose recursive traversal is enabled by default because the --depth option defaults to 0 (unlimited), as well as the recursive referrer counting used by the oras backup and oras restore workflows. A cyclic graph can be as simple as A referring to B and B referring back to A. A malicious registry can use this to cause a client-side denial of service, exhausting CPU and memory and hanging automation or CI/CD pipelines that run ORAS against untrusted registry metadata. The vulnerability does not extend to code execution, artifact substitution, or integrity bypass. This issue has been fixed in version 1.3.3.